CVE-2023-22644: JWT token compromise can allow malicious actions including Remote Code Execution (RCE)
A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE.
Other sources
An Innsertion of Sensitive Information into Log File vulnerability in SUSE SUSE Manager Server Module 4.2 spacewalk-java, SUSE SUSE Manager Server Module 4.3 spacewalk-java causes sensitive information to be logged. This issue affects SUSE Manager Server Module 4.2: before 4.2.50-150300.3.66.5; SUSE Manager Server Module 4.3: before 4.3.58-150400.3.46.4.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-22644?
CVE-2023-22644 is an Innsertion of Sensitive Information into Log File vulnerability affecting SUSE Manager Server Module 4.2 and 4.3.
How does CVE-2023-22644 impact SUSE Manager Server?
CVE-2023-22644 causes sensitive information to be logged in SUSE Manager Server.
What is the severity of CVE-2023-22644?
The severity of CVE-2023-22644 is medium, with a severity value of 5.5.
How can I fix CVE-2023-22644?
To fix CVE-2023-22644, update SUSE Manager Server Module 4.2 to version 4.2.50-150300.3.66.5 or later, and SUSE Manager Server Module 4.3 to version 4.3.58-150400.3.46.4 or later.
What is the CWE of CVE-2023-22644?
The CWE (Common Weakness Enumeration) of CVE-2023-22644 is 532.