CVE-2023-38037
Last modified
CVE-2023-38037 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. ActiveSupport::EncryptedFile writes contents that will be encrypted to a temporary file. The temporary file's permissions are defaulted to the user's current `umask` settings, meaning that it's possible for other users on the same system to read the contents of the temporary file. Attackers that have access to the file system could possibly read the contents of this temporary file while a user is editing it. All users running an affected release should either upgrade or use one of the workarounds immediately.. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
ActiveSupport::EncryptedFile writes contents that will be encrypted to a temporary file. The temporary file's permissions are defaulted to the user's current `umask` settings, meaning that it's possible for other users on the same system to read the contents of the temporary file. Attackers that have access to the file system could possibly read the contents of this temporary file while a user is editing it. All users running an affected release should either upgrade or use one of the workarounds immediately.
Metrics
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2023-38037?
How severe is CVE-2023-38037?
How do I fix CVE-2023-38037?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-38031 ASUS RT-AC86U Adaptive QoS - Web History function has insuf…8.8
- CVE-2023-38032 ASUS RT-AC86U AiProtection security- related function has i…8.8
- CVE-2023-38033 ASUS RT-AC86U unused Traffic Analyzer legacy Statistic func…8.8
- CVE-2023-38034A command injection vulnerability in the DHCP Client functio…9.8
- CVE-2023-38035A security vulnerability in MICS Admin Portal in Ivanti Mobi…9.8
- CVE-2023-38036A security vulnerability within Ivanti Avalanche Manager bef…9.8
- CVE-2023-38039When curl retrieves an HTTP response, it stores the incoming…7.5
- CVE-2023-3804A vulnerability classified as problematic was found in Cheng…9.8
- CVE-2023-38040A reflected XSS vulnerability exists in Revive Adserver 5.4.…6.1
- CVE-2023-38041A logged in user may elevate its permissions by abusing a Ti…7
- CVE-2023-38042A local privilege escalation vulnerability in Ivanti Secure …7.8
- CVE-2023-38043A vulnerability exists on all versions of the Ivanti Secure …7.8
Are you affected by CVE-2023-38037?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
