CVE-2023-27574: Critical severity shadowsocksx-ng vulnerability
Published Mar 3, 2023
·Updated
ShadowsocksX-NG 1.10.0 signs with com.apple.security.get-task-allow entitlements because of CODESIGNINGINJECTBASEENTITLEMENTS.
Affected Software
1 affected component
shadowsocks ShadowsocksX-NG=1.10.0
Remediation
Patch Available
Event History
Mar 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-27574?
The severity of CVE-2023-27574 is critical with a severity score of 9.8.
2
What is the affected software for CVE-2023-27574?
The affected software for CVE-2023-27574 is ShadowsocksX-NG version 1.10.0.
3
Why does ShadowsocksX-NG 1.10.0 sign with com.apple.security.get-task-allow entitlements?
ShadowsocksX-NG 1.10.0 signs with com.apple.security.get-task-allow entitlements due to CODE_SIGNING_INJECT_BASE_ENTITLEMENTS.
4
How can I fix CVE-2023-27574?
To fix CVE-2023-27574, update the affected software to a version that is not affected.
5
Where can I find more information about CVE-2023-27574?
More information about CVE-2023-27574 can be found at the following references: [GitHub](https://github.com/shadowsocks/ShadowsocksX-NG/pull/1456), [Shadowsocks](https://shadowsocks.org).