First published: Tue May 09 2023(Updated: )
Changes to user permissions in Portal for ArcGIS 10.9.1 and below are incompletely applied in specific use cases. This issue may allow users to access content that they are no longer privileged to access.
Credit: psirt@esri.com
Affected Software | Affected Version | How to fix |
---|---|---|
Esri Portal for ArcGIS | >=10.7.1<=10.9.1 |
Install P ortal for ArcGIS Security 2023 Update 1 https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/portal-for-arcgis-security-2023-update-1-patch-is-now-available/
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-25834.
Changes to user permissions in Portal for ArcGIS 10.9.1 and below are incompletely applied in specific use cases, allowing users to access content they are no longer privileged to access.
The severity rating of CVE-2023-25834 is medium with a score of 5.4.
To fix CVE-2023-25834, you need to install the Portal for ArcGIS Security 2023 Update 1 Patch, which is available from the Esri support website.
You can find more information about CVE-2023-25834 on the Esri support website and the Esri ArcGIS Blog.