CVE-2023-6916: Information disclosure via audit records for OpenAPI requests in Guardian/CMC before 23.4.1
Audit records for OpenAPI requests may include sensitive information.
This could lead to unauthorized accesses and privilege escalation.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6916?
CVE-2023-6916 is classified as a medium-severity vulnerability due to its potential for unauthorized access and privilege escalation.
How can I fix CVE-2023-6916?
To fix CVE-2023-6916, ensure you update the Guardian CMC software to a version later than 23.4.1 and review your audit logging configuration.
What are the risks associated with CVE-2023-6916?
The risks associated with CVE-2023-6916 include unauthorized access to sensitive information and potential privilege escalation.
Which software is affected by CVE-2023-6916?
CVE-2023-6916 affects the Guardian CMC software versions up to and including 23.4.1.
Is CVE-2023-6916 being actively exploited?
As of now, there are no confirmed reports of active exploitation for CVE-2023-6916, but it is advisable to apply security updates promptly.