First published: Wed Feb 01 2023(Updated: )
** DISPUTED **Connectwise Control 22.8.10013.8329 is vulnerable to Cross Origin Resource Sharing (CORS). The vendor's position is that two endpoints have Access-Control-Allow-Origin wildcarding to support product functionality, and that there is no risk from this behavior. The vulnerability report is thus not valid.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ConnectWise Manage | =22.8.10013.8329 | |
=22.8.10013.8329 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-23128 has not been officially classified, as the vendor disputes any risk presented by the vulnerability.
The vendor recommends utilizing the built-in security features and confirms that no immediate action is required for users of Connectwise Control 22.8.10013.8329.
CVE-2023-23128 potentially impacts Cross Origin Resource Sharing (CORS) functionality in Connectwise Control 22.8.10013.8329.
Currently, there is no evidence or reports indicating that CVE-2023-23128 is being actively exploited in the wild.
While the vendor asserts that there is no risk associated with CVE-2023-23128, administrators should remain vigilant and monitor for any updates from Connectwise.