CVE-2023-1663
Last modified
CVE-2023-1663 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Coverity versions prior to 2023.3.2 are vulnerable to forced browsing, which exposes authenticated resources to unauthorized actors. The root cause of this vulnerability is an insecurely configured servlet mapping for the underlying Apache Tomcat server. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
Coverity versions prior to 2023.3.2 are vulnerable to forced browsing, which exposes authenticated resources to unauthorized actors. The root cause of this vulnerability is an insecurely configured servlet mapping for the underlying Apache Tomcat server. As a result, the downloads directory and its contents are accessible. 5.9 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L/E:P/RL:O/RC:C)
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Synopsys | Coverity | < 2023.3.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-1663?
How severe is CVE-2023-1663?
How do I fix CVE-2023-1663?
Are you affected by CVE-2023-1663?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
