CVE-2023-43784: High severity Plesk Onyx vulnerability
DISPUTED Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE: the vendor's position is that there is no security threat.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-43784?
The severity of CVE-2023-43784 is high.
What is Plesk Onyx 17.8.11?
Plesk Onyx 17.8.11 is a version of the Plesk control panel software.
What is the impact of CVE-2023-43784?
CVE-2023-43784 can potentially expose accessKeyId and secretAccessKey related to an Amazon AWS Firehose, leading to unauthorized access or data breaches.
How can I mitigate the vulnerability in Plesk Onyx 17.8.11?
To mitigate the vulnerability in Plesk Onyx 17.8.11, it is recommended to disable or remove the accessKeyId and secretAccessKey fields related to the Amazon AWS Firehose component.
Where can I find more information about the vulnerability?
You can find more information about the vulnerability in CVE-2023-43784 from the official Amazon IAM User Guide and the Plesk community forum.