CVE-2023-37649: High severity Agentejo Cockpit vulnerability
Incorrect access control in the component /models/Content of Cockpit CMS v2.5.2 allows unauthorized attackers to access sensitive data.
Other sources
Incorrect access control in the component /models/Content of Cockpit CMS v2.5.2 allows unauthorized attackers to access sensitive data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/cockpit-hq/cockpitto a version that resolves this vulnerability.Fixed in 2.6.0
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-37649.
What is the severity of CVE-2023-37649?
The severity of CVE-2023-37649 is high, with a severity value of 7.5.
What is the affected software for CVE-2023-37649?
The affected software for CVE-2023-37649 is Agentejo Cockpit CMS v2.5.2 and composer/cockpit-hq/cockpit up to version 2.6.0.
What is the impact of CVE-2023-37649?
CVE-2023-37649 allows unauthorized attackers to access sensitive data due to incorrect access control in the component `/models/Content` of Cockpit CMS.
How can I fix CVE-2023-37649?
To fix CVE-2023-37649, update your Agentejo Cockpit CMS installation to version 2.6.0 or newer.