CVE-2023-41266: Qlik Sense Path Traversal Vulnerability
A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an unauthenticated remote attacker to generate an anonymous session. This allows them to transmit HTTP requests to unauthorized endpoints. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13.
Other sources
Qlik Sense contains a path traversal vulnerability that allows a remote, unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the attacker to send further requests to unauthorized endpoints.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Qlik Sense Enterprise for Windowsto a version that resolves this vulnerability.Fixed in August 2023 IR - Upgrade
Upgrade
Qlik Sense Enterprise for Windowsto a version that resolves this vulnerability.Patch May 2023 Patch 4 - Upgrade
Upgrade
Qlik Sense Enterprise for Windowsto a version that resolves this vulnerability.Patch February 2023 Patch 8 - Upgrade
Upgrade
Qlik Sense Enterprise for Windowsto a version that resolves this vulnerability.Patch November 2022 Patch 11 - Upgrade
Upgrade
Qlik Sense Enterprise for Windowsto a version that resolves this vulnerability.Patch August 2022 Patch 13
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this path traversal vulnerability?
The vulnerability ID for this path traversal vulnerability is CVE-2023-41266.
What is the severity of CVE-2023-41266?
The severity of CVE-2023-41266 is high.
Which software versions are affected by CVE-2023-41266?
The versions affected by CVE-2023-41266 are May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier.
How can an unauthenticated remote attacker exploit CVE-2023-41266?
An unauthenticated remote attacker can exploit CVE-2023-41266 by generating an anonymous session.
Where can I find more information about CVE-2023-41266?
You can find more information about CVE-2023-41266 at the following references: [link1](https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/ta-p/2110801) and [link2](https://community.qlik.com/t5/Release-Notes/tkb-p/ReleaseNotes).