Lucene search

K
nvd[email protected]NVD:CVE-2023-6562
HistoryDec 20, 2023 - 1:15 p.m.

CVE-2023-6562

2023-12-2013:15:07
CWE-434
CWE-22
web.nvd.nist.gov
1
kakadu 7.9
jpx fragment list
flst box
vulnerability
exfiltration
local files
remote files
server
upload
image

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.001 Low

EPSS

Percentile

37.1%

JPX Fragment List (flst) box vulnerability in Kakadu 7.9 allows an attacker to exfiltrate local and remote files reachable by a server if the server allows the attacker to upload a specially-crafted the image that is displayed back to the attacker.

Affected configurations

NVD
Node
kakadusoftwarekakadu_sdkRange4.48.4

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.001 Low

EPSS

Percentile

37.1%

Related for NVD:CVE-2023-6562