CVE-2023-46237: FOG path traversal via unauthenticated endpoint
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, an endpoint intended to offer limited enumeration abilities to authenticated users was accessible to unauthenticated users. This enabled unauthenticated users to discover files and their respective paths that were visible to the Apache user group. Version 1.5.10 contains a patch for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-46237.
What is the severity of CVE-2023-46237?
CVE-2023-46237 has a severity of medium (5.8).
What is the affected software for CVE-2023-46237?
The affected software for CVE-2023-46237 is Fogproject 1.5.10 and prior versions.
How can an unauthenticated user exploit CVE-2023-46237?
An unauthenticated user can exploit CVE-2023-46237 by accessing an endpoint that was intended for authenticated users, allowing them to discover files and their respective paths.
Are there any references for CVE-2023-46237?
Yes, you can find references for CVE-2023-46237 at the following links: [GitHub Advisory](https://github.com/FOGProject/fogproject/security/advisories/GHSA-ffp9-rhfm-98c2) and [GitHub Commit](https://github.com/FOGProject/fogproject/commit/68d73740d7d40aee77cfda3fb8199d58bf04f48b).