CVE-2023-48171: High severity owasp defectdojo vulnerability
Published Aug 12, 2024
·Updated
An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.
Affected Software
1 affected component
OWASP DefectDojo<1.5.3.1
Event History
Aug 12, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-48171?
CVE-2023-48171 is classified as a high severity vulnerability due to the potential for privilege escalation.
2
How do I fix CVE-2023-48171?
To fix CVE-2023-48171, update OWASP DefectDojo to version 1.5.3.1 or later.
3
What types of attacks are possible with CVE-2023-48171?
An attacker can exploit CVE-2023-48171 to escalate user privileges and gain unauthorized access to sensitive functionalities.
4
Which versions of OWASP DefectDojo are affected by CVE-2023-48171?
CVE-2023-48171 affects all versions of OWASP DefectDojo prior to 1.5.3.1.
5
Can CVE-2023-48171 lead to data breaches?
Yes, if exploited, CVE-2023-48171 can lead to unauthorized access and potentially result in data breaches.