PT-2023-6981 · Powerjob · Powerjob

Testnet0

·

Published

2023-04-19

·

Updated

2023-04-28

·

CVE-2023-29923

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PowerJob version 4.3.1
Description The issue is related to insecure permissions in the PowerJob platform, which can be exploited to gain unauthorized access to protected information. This can be done remotely through the list job interface.
Recommendations For PowerJob version 4.3.1, consider restricting access to the list job interface until a patch is available. As a temporary workaround, review and adjust the default permissions to prevent unauthorized access.

Exploit

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-08000
CVE-2023-29923
GHSA-5C86-GPVC-FP53

Affected Products

Powerjob