First published: Tue Jun 06 2023(Updated: )
Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain information to attack and leak further information from the Landscape API.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Canonical Landscape | <19.10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-32550 is a vulnerability in Landscape where the server-status page exposed sensitive system information.
CVE-2023-32550 has a severity value of 8.2, which is considered critical.
CVE-2023-32550 affects Canonical Landscape versions up to and excluding 19.10.5.
CVE-2023-32550 exposes sensitive information by leaking it through GET requests on the server-status page of Landscape.
You can find more information about CVE-2023-32550 at the following link: [CVE-2023-32550](https://bugs.launchpad.net/landscape/+bug/1929037)