CVE-2023-30856
Last modified
CVE-2023-30856 is a critical-severity vulnerability rated 10/10 on the CVSS scale. eDEX-UI is a science fiction terminal emulator. Versions 2.2.8 and prior are vulnerable to cross-site websocket hijacking. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
eDEX-UI is a science fiction terminal emulator. Versions 2.2.8 and prior are vulnerable to cross-site websocket hijacking. When running eDEX-UI and browsing the web, a malicious website can connect to eDEX's internal terminal control websocket, and send arbitrary commands to the shell. The project has been archived since 2021, and as of time of publication there are no plans to patch this issue and release a new version. Some workarounds are available, including shutting down eDEX-UI when browsing the web and ensuring the eDEX terminal runs with lowest possible privileges.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Edex-Ui Project | Edex-Ui | <= 2.2.8 |
References
- https://christian-schneider.net/CrossSiteWebSocketHijacking.htmlTechnical Description
- https://christian-schneider.net/CrossSiteWebSocketHijacking.htmlTechnical Description
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-30856?
How severe is CVE-2023-30856?
How do I fix CVE-2023-30856?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-30850Pimcore is an open source data and experience management pla…8.8
- CVE-2023-30851Cilium is a networking, observability, and security solution…5.3
- CVE-2023-30852Pimcore is an open source data and experience management pla…4.9
- CVE-2023-30853Gradle Build Action allows users to execute a Gradle Build i…6.5
- CVE-2023-30854AVideo is an open source video platform. Prior to version 12…8.8
- CVE-2023-30855Pimcore is an open source data and experience management pla…7.5
- CVE-2023-30857@aedart/support is the support package for Ion, a monorepo f…3.7
- CVE-2023-30858The Denosaurs emoji package provides emojis for dinosaurs. S…7.5
- CVE-2023-30859Triton is a Minecraft plugin for Spigot and BungeeCord that …9.8
- CVE-2023-3086Cross-site Scripting (XSS) - Stored in GitHub repository nil…9
- CVE-2023-30860WWBN AVideo is an open source video platform. In AVideo prio…5.4
- CVE-2023-30861Flask is a lightweight WSGI web application framework. When …7.5
Are you affected by CVE-2023-30856?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
