PT-2023-28991 · Altair · Altair

Masood

·

Published

2023-10-04

·

Updated

2023-10-10

·

CVE-2023-43799

CVSS v3.1

5.0

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Altair versions prior to 5.2.5
Description The Altair GraphQL Client Desktop Application does not sanitize external URLs before passing them to the underlying system and does not isolate the context of the renderer process. This issue affects versions of the software running on MacOS, Windows, and Linux.
Recommendations For versions prior to 5.2.5, update to version 5.2.5 to resolve the issue. As a temporary workaround, consider restricting access to external URLs and isolating the renderer process context until the update is applied.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2023-43799
GHSA-9M5V-VRF6-FMVM

Affected Products

Altair