CVE-2023-34125: Path Traversal
Path Traversal vulnerability in GMS and Analytics allows an authenticated attacker to read arbitrary files from the underlying filesystem with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GMSto a version that resolves this vulnerability.Fixed in 9.3.2-SP1 - Upgrade
Upgrade
Analyticsto a version that resolves this vulnerability.Fixed in 2.5.0.4-R7
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-34125.
What is the severity of CVE-2023-34125?
The severity of CVE-2023-34125 is medium with a CVSS score of 6.5.
Which software versions are affected by CVE-2023-34125?
CVE-2023-34125 affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
How does the vulnerability in GMS and Analytics manifest?
The vulnerability in GMS and Analytics is a path traversal vulnerability that allows an authenticated attacker to read arbitrary files from the underlying filesystem with root privileges.
How can I fix CVE-2023-34125?
To fix CVE-2023-34125, update GMS to version 9.3.2-SP2 or later, and update Analytics to version 3.0.0.1-R1 or later.