CVE-2023-35937
Last modified
CVE-2023-35937 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Metersphere is an open source continuous testing platform. In versions prior to 2.10.2 LTS, some key APIs in Metersphere lack permission checks. EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
Metersphere is an open source continuous testing platform. In versions prior to 2.10.2 LTS, some key APIs in Metersphere lack permission checks. This allows ordinary users to execute APIs that can only be executed by space administrators or project administrators. For example, ordinary users can be updated as space administrators. Version 2.10.2 LTS has a patch for this issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Metersphere | Metersphere | < 2.10.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-35937?
How severe is CVE-2023-35937?
How do I fix CVE-2023-35937?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-35931Shescape is a simple shell escape library for JavaScript. An…4.3
- CVE-2023-35932jcvi is a Python library to facilitate genome assembly, anno…8.8
- CVE-2023-35933OPenFGA is an open source authorization/permission engine bu…7.5
- CVE-2023-35934yt-dlp is a command-line program to download videos from vid…8.2
- CVE-2023-35935Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2023-35936Pandoc is a Haskell library for converting from one markup f…5
- CVE-2023-35938 Tuleap is a Free & Open Source Suite to improve management …7.2
- CVE-2023-35939GLPI is a free asset and IT management software package. Sta…8.1
- CVE-2023-35940GLPI is a free asset and IT management software package. Sta…7.5
- CVE-2023-35941Envoy is an open source edge and service proxy designed for …9.8
- CVE-2023-35942Envoy is an open source edge and service proxy designed for …6.5
- CVE-2023-35943Envoy is an open source edge and service proxy designed for …7.5
Are you affected by CVE-2023-35937?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
