CVE-2023-29860: High severity dtstack taier vulnerability
Published Jun 23, 2023
·Updated
An insecure permissions in /Taier/API/tenant/listTenant interface in DTStack Taier 1.3.0 allows attackers to view sensitive information via the getCookie method.
Affected Software
1 affected component
DTStack Taier=1.3.0
Event History
Jun 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-29860?
CVE-2023-29860 has a high severity rating of 7.5 according to CVSS 3.1.
2
How do I fix CVE-2023-29860?
To mitigate CVE-2023-29860, you should update DTStack Taier to the latest version that addresses this vulnerability.
3
What type of vulnerability is CVE-2023-29860?
CVE-2023-29860 is categorized as an insecure permissions vulnerability that allows unauthorized access to sensitive information.
4
What impact does CVE-2023-29860 have on DTStack Taier?
CVE-2023-29860 could potentially allow attackers to view sensitive information, compromising the confidentiality of data.
5
In which component of DTStack Taier is CVE-2023-29860 present?
CVE-2023-29860 is present in the /Taier/API/tenant/listTenant interface of DTStack Taier.