Lucene search

K
cvelistJpcertCVELIST:CVE-2023-38752
HistoryAug 09, 2023 - 3:29 a.m.

CVE-2023-38752

2023-08-0903:29:51
jpcert
www.cve.org
vulnerability
authorization
special interest group network for analysis and liaison
api
non-disclosure

4.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.2%

Improper authorization vulnerability in Special Interest Group Network for Analysis and Liaison versions 4.4.0 to 4.7.7 allows the authorized API users to view the attribute information of the poster that is set as"non-disclosure" in the system settings.

CNA Affected

[
  {
    "vendor": "Japan Computer Emergency Response Team Coordination Center (JPCERT/CC)",
    "product": "Special Interest Group Network for Analysis and Liaison ",
    "versions": [
      {
        "version": "versions 4.4.0 to 4.7.7 ",
        "status": "affected"
      }
    ]
  }
]

4.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.2%

Related for CVELIST:CVE-2023-38752