First published: Fri Aug 04 2023(Updated: )
CloudExplorer Lite is an open source, lightweight cloud management platform. Versions prior to 1.3.1 contain a command injection vulnerability in the installation function in module management. The vulnerability has been fixed in v1.3.1. There are no known workarounds aside from upgrading.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fit2cloud Cloudexplorer Lite | <1.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38692 is a command injection vulnerability in the installation function in module management in CloudExplorer Lite versions prior to 1.3.1.
CVE-2023-38692 has a severity score of 9.8 out of 10, indicating a critical vulnerability.
The vulnerability can be fixed by upgrading CloudExplorer Lite to version 1.3.1 or later.
There are no known workarounds for CVE-2023-38692 aside from upgrading to a fixed version.
You can find more information about CVE-2023-38692 at the following references: [link1], [link2], [link3].