PT-2024-13722 · Anomali · Anomali Match

Abdulmalik Aljurayyad

·

Published

2024-01-19

·

Updated

2024-01-26

·

CVE-2023-49329

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Anomali Match versions prior to 4.6.2
Description The issue arises from improper handling of untrusted input, enabling an attacker to inject and execute operating system commands. An authenticated admin user can elevate privileges, execute system commands, and potentially compromise the underlying operating system.
Recommendations For versions prior to 4.4.5, update to version 4.4.5 or later. For versions 4.4.5 through 4.5.3, update to version 4.5.4 or later. For versions 4.5.4 through 4.6.1, update to version 4.6.2.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2023-49329

Affected Products

Anomali Match