CVE-2023-2360: High severity acronis cyber infrastructure vulnerability
Sensitive information disclosure due to CORS misconfiguration. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.2.0-135.
Affected Software
Event History
Frequently Asked Questions
What is the nature of vulnerability CVE-2023-2360?
The vulnerability CVE-2023-2360 is a sensitive information disclosure vulnerability caused by a misconfiguration of CORS (Cross-Origin Resource Sharing).
Which products are affected by vulnerability CVE-2023-2360?
The products affected by vulnerability CVE-2023-2360 include Acronis Cyber Infrastructure (ACI) before version 5.2.0-135.
What is the severity of vulnerability CVE-2023-2360?
The severity of vulnerability CVE-2023-2360 is high, with a severity score of 7.5.
How can I fix vulnerability CVE-2023-2360?
To fix vulnerability CVE-2023-2360, update Acronis Cyber Infrastructure to version 5.2.0-135 or later and properly configure CORS settings to restrict cross-origin access.
Where can I find more information about vulnerability CVE-2023-2360?
For more information about vulnerability CVE-2023-2360, you can refer to the following reference: https://security-advisory.acronis.com/advisories/SEC-4215