First published: Thu Mar 21 2024(Updated: )
A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.1 by reducing the information sent in requests.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Claris Pro | ||
FileMaker Server | <20.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-42954 is classified as a privilege escalation vulnerability that may expose sensitive information.
To fix CVE-2023-42954, update to FileMaker Server version 20.3.1 or later.
CVE-2023-42954 affects Claris Pro and FileMaker Server versions prior to 20.3.1.
CVE-2023-42954 could potentially expose sensitive information to front-end websites when accessing the Admin Console.
No official workaround is provided for CVE-2023-42954; the best course of action is to perform the software update.