CVE-2023-24471: Information disclosure via the debug function in assertions in Guardian/CMC before 22.6.2
An access control vulnerability was found, due to the restrictions that are applied on actual assertions not being enforced in their debug functionality.
An authenticated user with reduced visibility can obtain unauthorized information via the debug functionality, obtaining data that would normally be not accessible in the Query and Assertions functions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this access control vulnerability?
The vulnerability ID is CVE-2023-24471.
What is the severity rating of CVE-2023-24471?
The severity rating of CVE-2023-24471 is medium.
How does the vulnerability affect Nozominetworks Cmc and Guardian?
The vulnerability affects Nozominetworks Cmc and Guardian versions up to and exclusive of 22.6.2.
How can an attacker exploit this vulnerability?
An authenticated user with reduced visibility can obtain unauthorized information via the debug functionality, obtaining data that would normally be restricted.
Is there a fix available for CVE-2023-24471?
To fix CVE-2023-24471, it is recommended to update Nozominetworks Cmc and Guardian to a version higher than 22.6.2.