CVE-2023-0214: XSS in Skyhigh Security SWG
A cross-site scripting vulnerability in Skyhigh SWG in main releases 11.x prior to 11.2.6, 10.x prior to 10.2.17, and controlled release 12.x prior to 12.0.1 allows a remote attacker to craft SWG-specific internal requests with URL paths to any third-party website, causing arbitrary content to be injected into the response when accessed through SWG.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0214?
The severity of CVE-2023-0214 is medium with a CVSS score of 6.1.
How does CVE-2023-0214 affect Trellix Skyhigh Secure Web Gateway?
CVE-2023-0214 affects Trellix Skyhigh Secure Web Gateway versions 10.x, 11.x, and 12.0.0.
What is the impact of CVE-2023-0214?
CVE-2023-0214 allows a remote attacker to inject arbitrary content into the website and potentially steal sensitive information or perform other malicious actions.
Is there a fix available for CVE-2023-0214?
Yes, a fix is available for CVE-2023-0214. Users should update their Trellix Skyhigh Secure Web Gateway to versions 10.2.17, 11.2.6, or 12.0.1.
Where can I find more information about CVE-2023-0214?
More information about CVE-2023-0214 can be found at the following link: https://kcm.trellix.com/corporate/index?page=content&id=SB10393