First published: Tue Jul 25 2023(Updated: )
Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Personal Data Fields. This issue affects Command Centre: vEL 8.90 prior to vEL8.90.1318 (MR1), vEL8.80 prior to vEL8.80.1192 (MR2), vEL8.70 prior to vEL8.70.2185 (MR4), vEL8.60 prior to vEL8.60.2347 (MR6), vEL8.50 prior to vEL8.50.2831 (MR8), all versions vEL8.40 and prior
Credit: disclosures@gallagher.com disclosures@gallagher.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gallagher Command Centre | <=8.40.2216 | |
Gallagher Command Centre | >=8.50<8.50.2831 | |
Gallagher Command Centre | >=8.60<8.60.2347 | |
Gallagher Command Centre | >=8.70<8.70.2185 | |
Gallagher Command Centre | >=8.80<8.80.1192 | |
Gallagher Command Centre | >=8.90<8.90.1318 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23568 is a vulnerability in Command Centre Server that allows authenticated unprivileged operators to modify and view Personal Data Fields.
The following versions of Command Centre are affected: vEL8.40.2216, vEL8.50 (up to vEL8.50.2831), vEL8.60 (up to vEL8.60.2347), vEL8.70 (up to vEL8.70.2185), vEL8.80 (up to vEL8.80.1192), vEL8.90 (up to vEL8.90.1318).
The severity of CVE-2023-23568 is medium, with a CVSS score of 5.4.
To fix CVE-2023-23568, update Command Centre to the latest version available, which contains the necessary security patches.
You can find more information about CVE-2023-23568 on the Gallagher Security Advisories website: [https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2023-23568](https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2023-23568).