First published: Fri Apr 28 2023(Updated: )
Sensitive information disclosure due to CORS misconfiguration. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.2.0-135.
Credit: security@acronis.com
Affected Software | Affected Version | How to fix |
---|---|---|
Acronis Cyber Infrastructure | <5.2.0-135 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability CVE-2023-2360 is a sensitive information disclosure vulnerability caused by a misconfiguration of CORS (Cross-Origin Resource Sharing).
The products affected by vulnerability CVE-2023-2360 include Acronis Cyber Infrastructure (ACI) before version 5.2.0-135.
The severity of vulnerability CVE-2023-2360 is high, with a severity score of 7.5.
To fix vulnerability CVE-2023-2360, update Acronis Cyber Infrastructure to version 5.2.0-135 or later and properly configure CORS settings to restrict cross-origin access.
For more information about vulnerability CVE-2023-2360, you can refer to the following reference: https://security-advisory.acronis.com/advisories/SEC-4215