First published: Tue Dec 12 2023(Updated: )
## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-m8rw-rcpq-2vp2. This link is maintained to preserve external references. ## Original Description SAP BTP Security Services Integration Library ([Golang] github.com/sap/cloud-security-client-go) - versions < 0.17.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.
Credit: cna@sap.com cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/sap/cloud-security-client-go | <0.17.0 | 0.17.0 |
Sap Cloud-security-client-go | <0.17.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-50424 is critical with a CVSS score of 9.1.
An unauthenticated attacker can exploit CVE-2023-50424 to obtain arbitrary permissions within the application.
Versions of the SAP BTP Security Services Integration Library ([Golang] github.com/sap/cloud-security-client-go) below 0.17.0 are affected by CVE-2023-50424.
You can find more information about CVE-2023-50424 in the provided references by SAP.