First published: Tue Nov 28 2023(Updated: )
Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specific configuration of metadata-driven permissions in M-Files Server versions 23.9, 23.10, and 23.11 before 23.11.13168.7, potentially enabling unauthorized access to the object.
Credit: security@m-files.com
Affected Software | Affected Version | How to fix |
---|---|---|
M-files M-files Server | >=23.11<23.11.13168.7 | |
M-files M-files Server | =23.9 | |
M-files M-files Server | =23.10 |
Update to patched version
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6239 is a vulnerability in M-Files Server versions 23.9, 23.10, and 23.11 before 23.11.13168.7 that allows for incorrect calculation of effective permissions, potentially enabling unauthorized access to objects.
The severity of CVE-2023-6239 is high with a CVSS score of 8.8.
CVE-2023-6239 affects M-Files Server versions 23.9, 23.10, and 23.11 before 23.11.13168.7 by potentially enabling unauthorized access to objects due to incorrect calculation of effective permissions.
To fix CVE-2023-6239, it is recommended to update M-Files Server to version 23.11.13168.7 or later.
More information about CVE-2023-6239 can be found at the following link: [https://www.m-files.com/about/trust-center/security-advisories/cve-2023-6239/](https://www.m-files.com/about/trust-center/security-advisories/cve-2023-6239/)