Lucene search

K
cveGitHub_MCVE-2023-48708
HistoryNov 24, 2023 - 6:15 p.m.

CVE-2023-48708

2023-11-2418:15:07
CWE-532
GitHub_M
web.nvd.nist.gov
19
codeigniter
shield
authentication
authorization
security issue
cve-2023-48708
upgrade advice

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

41.3%

CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. In affected versions successful login attempts are recorded with the raw tokens stored in the log table. If a malicious person somehow views the data in the log table they can obtain a raw token which can then be used to send a request with that user’s authority. This issue has been addressed in version 1.0.0-beta.8. Users are advised to upgrade. Users unable to upgrade should disable logging for successful login attempts by the configuration files.

Affected configurations

Nvd
Vulners
Node
codeignitershieldMatch1.0.0beta
OR
codeignitershieldMatch1.0.0beta2
OR
codeignitershieldMatch1.0.0beta3
OR
codeignitershieldMatch1.0.0beta4
OR
codeignitershieldMatch1.0.0beta5
OR
codeignitershieldMatch1.0.0beta6
OR
codeignitershieldMatch1.0.0beta7
VendorProductVersionCPE
codeignitershield1.0.0cpe:2.3:a:codeigniter:shield:1.0.0:beta:*:*:*:*:*:*
codeignitershield1.0.0cpe:2.3:a:codeigniter:shield:1.0.0:beta2:*:*:*:*:*:*
codeignitershield1.0.0cpe:2.3:a:codeigniter:shield:1.0.0:beta3:*:*:*:*:*:*
codeignitershield1.0.0cpe:2.3:a:codeigniter:shield:1.0.0:beta4:*:*:*:*:*:*
codeignitershield1.0.0cpe:2.3:a:codeigniter:shield:1.0.0:beta5:*:*:*:*:*:*
codeignitershield1.0.0cpe:2.3:a:codeigniter:shield:1.0.0:beta6:*:*:*:*:*:*
codeignitershield1.0.0cpe:2.3:a:codeigniter:shield:1.0.0:beta7:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "codeigniter4",
    "product": "shield",
    "versions": [
      {
        "version": "< 1.0.0-beta.8",
        "status": "affected"
      }
    ]
  }
]

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

41.3%

Related for CVE-2023-48708