CVE-2023-32550: Landscape's Apache server-status is accessible by default
Published Jun 6, 2023
·Updated
Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain information to attack and leak further information from the Landscape API.
Affected Software
1 affected component
Canonical Landscape<19.10.5
Event History
Jun 6, 2023
CVE Published
via MITRE·03:07 PM
Data Sourced
via MITRE·03:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-32550?
CVE-2023-32550 is a vulnerability in Landscape where the server-status page exposed sensitive system information.
2
What is the severity of CVE-2023-32550?
CVE-2023-32550 has a severity value of 8.2, which is considered critical.
3
What software versions are affected by CVE-2023-32550?
CVE-2023-32550 affects Canonical Landscape versions up to and excluding 19.10.5.
4
How does CVE-2023-32550 expose sensitive information?
CVE-2023-32550 exposes sensitive information by leaking it through GET requests on the server-status page of Landscape.
5
Where can I find more information about CVE-2023-32550?
You can find more information about CVE-2023-32550 at the following link: [CVE-2023-32550](https://bugs.launchpad.net/landscape/+bug/1929037)