CVE-2023-25834: BUG-000142922 Incomplete permission changes in specific cases.
Published May 9, 2023
·Updated
Changes to user permissions in Portal for ArcGIS 10.9.1 and below are incompletely applied in specific use cases. This issue may allow users to access content that they are no longer privileged to access.
Affected Software
1 affected component
Esri Portal for ArcGIS>=10.7.1<=10.9.1
Remediation
Information
Install P ortal for ArcGIS Security 2023 Update 1 https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/portal-for-arcgis-security-2023-update-1-patch-is-now-available/
Event History
May 9, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2023-25834.
2
What is the description of CVE-2023-25834?
Changes to user permissions in Portal for ArcGIS 10.9.1 and below are incompletely applied in specific use cases, allowing users to access content they are no longer privileged to access.
3
What is the severity rating of CVE-2023-25834?
The severity rating of CVE-2023-25834 is medium with a score of 5.4.
4
How can I fix CVE-2023-25834?
To fix CVE-2023-25834, you need to install the Portal for ArcGIS Security 2023 Update 1 Patch, which is available from the Esri support website.
5
Where can I find more information about CVE-2023-25834?
You can find more information about CVE-2023-25834 on the Esri support website and the Esri ArcGIS Blog.