CVE-2023-22320: Path Traversal
Published Jan 10, 2023
·Updated
OpenAM Web Policy Agent (OpenAM Consortium Edition) provided by OpenAM Consortium parses URLs improperly, leading to a path traversal vulnerability(CWE-22). Furthermore, a crafted URL may be evaluated incorrectly.
Affected Software
1 affected component
OpenAM OpenAM=4.1.0
Event History
Jan 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-22320?
CVE-2023-22320 is classified as a critical severity vulnerability due to its potential for unauthorized file access.
2
How do I fix CVE-2023-22320?
To fix CVE-2023-22320, it is recommended to update to the latest version of OpenAM that has addressed the vulnerability.
3
What types of attacks can be executed through CVE-2023-22320?
CVE-2023-22320 can be exploited for path traversal attacks, allowing attackers to access restricted files on the server.
4
Which versions of OpenAM are affected by CVE-2023-22320?
CVE-2023-22320 specifically affects OpenAM version 4.1.0.
5
What are the consequences of exploiting CVE-2023-22320?
Exploitation of CVE-2023-22320 can result in unauthorized information disclosure and potential system compromise.