Lucene search

K
cveMitreCVE-2023-49706
HistoryDec 19, 2023 - 7:15 p.m.

CVE-2023-49706

2023-12-1919:15:07
CWE-362
mitre
web.nvd.nist.gov
26
cve-2023-49706
security vulnerability
privilege escalation
linotp 3.x
self service
api
race condition

CVSS3

6.8

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

42.1%

Defective request context handling in Self Service in LinOTP 3.x before 3.2.5 allows remote unauthenticated attackers to escalate privileges, thereby allowing them to act as and with the permissions of another user. Attackers must generate repeated API requests to trigger a race condition with concurrent user activity in the self-service portal.

Affected configurations

Nvd
Node
linotplinotpRange3.0.03.2.4
Node
linotpvirtual_applianceRange3.0.03.2.4
VendorProductVersionCPE
linotplinotp*cpe:2.3:a:linotp:linotp:*:*:*:*:*:*:*:*
linotpvirtual_appliance*cpe:2.3:a:linotp:virtual_appliance:*:*:*:*:*:*:*:*

CVSS3

6.8

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

42.1%

Related for CVE-2023-49706