CVE-2023-35154: Knowage-Server vulnerable to account validation bypass
Knowage is an open source analytics and business intelligence suite. Starting in version 6.0.0 and prior to version 8.1.8, an attacker can register and activate their account without having to click on the link included in the email, allowing them access to the application as a normal user. This issue has been patched in version 8.1.8.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Knowage-Serverto a version that resolves this vulnerability.Fixed in 8.1.8
Event History
Frequently Asked Questions
What is the severity of CVE-2023-35154?
CVE-2023-35154 is classified as a high severity vulnerability due to unauthorized account activation allowing potential access to sensitive application data.
How do I fix CVE-2023-35154?
To fix CVE-2023-35154, upgrade Knowage to version 8.1.8 or later to mitigate the account registration vulnerability.
What versions of Knowage are affected by CVE-2023-35154?
All versions of Knowage from 6.0.0 to 8.1.7 are affected by CVE-2023-35154.
Can an attacker exploit CVE-2023-35154 remotely?
Yes, an attacker can remotely exploit CVE-2023-35154 by registering an account without email confirmation.
What are the potential impacts of CVE-2023-35154?
The potential impacts of CVE-2023-35154 include unauthorized access to the application and exposure of sensitive data.