First published: Mon Jul 24 2023(Updated: )
Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Competencies. This issue affects Command Centre: vEL8.90 prior to vEL8.90.1318 (MR1), vEL8.80 prior to vEL8.80.1192 (MR2), vEL8.70 prior to vEL8.70.2185 (MR4), vEL8.60 prior to vEL8.60.2347 (MR6), vEL8.50 prior to vEL8.50.2831 (MR8), all versions vEL8.40 and prior.
Credit: disclosures@gallagher.com disclosures@gallagher.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gallagher Command Centre | <=8.40.2216 | |
Gallagher Command Centre | >=8.50<8.50.2831 | |
Gallagher Command Centre | >=8.60<8.60.2347 | |
Gallagher Command Centre | >=8.70<8.70.2185 | |
Gallagher Command Centre | >=8.80<8.80.1192 | |
Gallagher Command Centre | >=8.90<8.90.1318 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25074 is a vulnerability in Command Centre Server that allows authenticated unprivileged operators to modify and view Competencies.
Versions vEL8.90 prior to vEL8.90.1318 (MR1), vEL8.80 prior to vEL8.80.1192 (MR2), vEL8.70 prior to vEL8.70.2185 (MR4), vEL8.60 prior to vEL8.60.2347, vEL8.50 prior to vEL8.50.2831, and vEL8.40 prior to vEL8.40.2216 are affected by CVE-2023-25074.
CVE-2023-25074 has a severity rating of 5.4 (Moderate).
To fix CVE-2023-25074, it is recommended to upgrade to a patched version of Command Centre Server.
You can find more information about CVE-2023-25074 on the [Gallagher Security Advisories](https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2023-25074) website.