CVE-2023-40788: Medium severity bladex springblade vulnerability
SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthorized access to error logs
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-40788?
CVE-2023-40788 is a vulnerability in SpringBlade <=V3.6.0 that allows unauthorized access to error logs due to incorrect access control configuration in the default gateway.
How severe is CVE-2023-40788?
CVE-2023-40788 has a severity rating of medium with a CVSS score of 5.3.
How can I fix CVE-2023-40788?
To fix CVE-2023-40788, update to a version of SpringBlade that is higher than V3.6.0.
Where can I find more information about CVE-2023-40788?
You can find more information about CVE-2023-40788 on the following references: [Reference 1](https://gist.github.com/kaliwin/89276ec7e97f9529c989bd77706c29c7), [Reference 2](https://github.com/chillzhuang/SpringBlade), [Reference 3](https://github.com/chillzhuang/SpringBlade/blob/master/blade-gateway/src/main/java/org/springblade/gateway/provider/AuthProvider.java).
What is the Common Weakness Enumeration (CWE) for CVE-2023-40788?
The Common Weakness Enumeration (CWE) for CVE-2023-40788 is CWE-668.