CVE-2023-42361
Last modified
CVE-2023-42361 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Local File Inclusion vulnerability in Midori-global Better PDF Exporter for Jira Server and Jira Data Center v.10.3.0 and before allows an attacker to view arbitrary files and cause other impacts via use of crafted image during PDF export.. EPSS estimates a 0.93% chance of exploitation in the next 30 days.
Description
Local File Inclusion vulnerability in Midori-global Better PDF Exporter for Jira Server and Jira Data Center v.10.3.0 and before allows an attacker to view arbitrary files and cause other impacts via use of crafted image during PDF export.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Midori-Global | Better Pdf Exporter | < 11.0.0 |
References
- https://gccybermonks.com/posts/pdfjira/Third Party Advisory
- https://gccybermonks.com/posts/pdfjira/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-42361?
How severe is CVE-2023-42361?
How do I fix CVE-2023-42361?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-42345A Cross Site Scripting vulnerability in Alkacon OpenCms befo…6.1
- CVE-2023-42346Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> ref…7.5
- CVE-2023-4235A flaw was found in ofono, an Open Source Telephony on Linux…8.1
- CVE-2023-42358An issue was discovered in O-RAN Software Community ric-plt-…7.7
- CVE-2023-42359SQL injection vulnerability in Exam Form Submission in PHP w…9.8
- CVE-2023-4236A flaw in the networking code handling DNS-over-TLS queries …7.5
- CVE-2023-42362An arbitrary file upload vulnerability in Teller Web App v.4…5.4
- CVE-2023-42363A use-after-free vulnerability was discovered in xasprintf f…5.5
- CVE-2023-42364A use-after-free vulnerability in BusyBox v.1.36.1 allows at…5.5
- CVE-2023-42365A use-after-free vulnerability was discovered in BusyBox v.1…5.5
- CVE-2023-42366A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in…5.5
- CVE-2023-4237A flaw was found in the Ansible Automation Platform. When cr…7.8
Are you affected by CVE-2023-42361?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
