CVE-2023-47321: Medium severity Silverpeas Silverpeas vulnerability
Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control via the "Porlet Deployer" which allows administrators to deploy .WAR portlets.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.silverpeas.core:silverpeas-core-webto a version that resolves this vulnerability.Fixed in 6.3.2
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47321?
CVE-2023-47321 is classified as a high severity vulnerability due to incorrect access control in Silverpeas Core 6.3.1.
How do I fix CVE-2023-47321?
To remediate CVE-2023-47321, upgrade Silverpeas Core to version 6.3.2 or later.
What impact does CVE-2023-47321 have on my system?
CVE-2023-47321 allows unauthorized deployment of .WAR portlets, potentially compromising the security of applications.
Which versions of Silverpeas Core are affected by CVE-2023-47321?
Silverpeas Core versions prior to 6.3.2, specifically 6.3.1, are affected by CVE-2023-47321.
Is CVE-2023-47321 a remote exploit?
CVE-2023-47321 can be exploited remotely by administrative users if access controls are not properly enforced.