CVE-2023-44397: CloudExplorer Lite permission bypass vulnerability
CloudExplorer Lite is an open source, lightweight cloud management platform. Prior to version 1.4.1, the gateway filter of CloudExplorer Lite uses a controller with path starting with matching/API/, which can cause a permission bypass. Version 1.4.1 contains a patch for this issue.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-44397?
CVE-2023-44397 is a vulnerability in CloudExplorer Lite that allows for permission bypass.
How severe is CVE-2023-44397?
CVE-2023-44397 has a severity rating of 9.8 (critical).
What is affected by CVE-2023-44397?
CloudExplorer Lite versions up to 1.4.1 are affected by CVE-2023-44397.
How can I fix CVE-2023-44397?
To fix CVE-2023-44397, update CloudExplorer Lite to version 1.4.1 or later.
Where can I find more information about CVE-2023-44397?
More information about CVE-2023-44397 can be found in the advisory on GitHub: [link](https://github.com/CloudExplorer-Dev/CloudExplorer-Lite/security/advisories/GHSA-fqxr-7g94-vrfj)