CVE-2023-36106: High severity powerjob vulnerability
An incorrect access control vulnerability in powerjob 4.3.2 and earlier allows remote attackers to obtain sensitive information via the interface for querying via appId parameter to /container/list.
Other sources
An incorrect access control vulnerability in powerjob 4.3.2 and earlier allows remote attackers to obtain sensitive information via the interface for querying via appId parameter to /container/list.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-36106?
CVE-2023-36106 has been rated as a medium severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2023-36106?
To fix CVE-2023-36106, upgrade to Powerjob version 4.3.3 or later, where the incorrect access control is addressed.
What systems are affected by CVE-2023-36106?
CVE-2023-36106 affects Powerjob versions up to and including 4.3.2.
What type of information can be exposed through CVE-2023-36106?
CVE-2023-36106 allows remote attackers to obtain sensitive application information through improper access control.
Who can exploit CVE-2023-36106?
CVE-2023-36106 can be exploited by remote attackers who have access to the application's querying interface.