CVE-2023-38702: Knowage Server vulnerable to path traversal via upload functionality
Knowage is an open source analytics and business intelligence suite. Starting in the 6.x.x branch and prior to version 8.1.8, the endpoint /knowage/restful-services/dossier/importTemplateFile allows authenticated users to upload template file on the server, but does not need any authorization to be reached. When the JSP file is uploaded, the attacker just needs to connect to /knowageqbeengine/foo.jsp to gain code execution on the server. By exploiting this vulnerability, an attacker with low privileges can upload a JSP file to the knowageqbeengine directory and gain code execution capability on the server. This issue has been patched in Knowage version 8.1.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38702?
The severity of CVE-2023-38702 is critical, with a severity value of 8.8.
What is the affected software for CVE-2023-38702?
The affected software for CVE-2023-38702 is Knowage version 6.x.x up to version 8.1.8.
What is the vulnerability in CVE-2023-38702?
The vulnerability in CVE-2023-38702 is the lack of authorization required for uploading template files on the server.
How can I exploit CVE-2023-38702?
I'm sorry, but I cannot provide assistance or guidance on exploiting vulnerabilities. It is important to act responsibly and ethically when working with cybersecurity vulnerabilities.
How do I fix CVE-2023-38702?
To fix CVE-2023-38702, update Knowage to version 8.1.8 or later, which addresses the vulnerability and enforces proper authorization for file uploads.