CVE-2023-45152
Last modified
CVE-2023-45152 is a low-severity vulnerability rated 2.3/10 on the CVSS scale. Engelsystem is a shift planning system for chaos events. A Blind SSRF in the "Import schedule" functionality makes it possible to perform a port scan against the local environment. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
Engelsystem is a shift planning system for chaos events. A Blind SSRF in the "Import schedule" functionality makes it possible to perform a port scan against the local environment. This vulnerability has been fixed in commit ee7d30b33. If a patch cannot be deployed, operators should ensure that no HTTP(s) services listen on localhost and/or systems only reachable from the host running the engelsystem software. If such services are necessary, they should utilize additional authentication.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Engelsystem | Engelsystem | < 2023-09-18 |
References
- https://github.com/engelsystem/engelsystem/security/advisories/GHSA-jj9g-75wf-6ppfExploit, Third Party Advisory
- https://github.com/engelsystem/engelsystem/security/advisories/GHSA-jj9g-75wf-6ppfExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-45152?
How severe is CVE-2023-45152?
How do I fix CVE-2023-45152?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-45147Discourse is an open source community platform. In affected …3.1
- CVE-2023-45148Nextcloud is an open source home cloud server. When Memcache…4.3
- CVE-2023-45149Nextcloud talk is a chat module for the Nextcloud server pla…4.3
- CVE-2023-4515In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2023-45150Nextcloud calendar is a calendar app for the Nextcloud serve…4.3
- CVE-2023-45151Nextcloud server is an open source home cloud platform. Affe…8.8
- CVE-2023-45158An OS command injection vulnerability exists in web2py 2.24.…9.8
- CVE-2023-451591E Client installer can perform arbitrary file deletion on p…8.4
- CVE-2023-4516 A CWE-306: Missing Authentication for Critical Function vul…7.8
- CVE-2023-45160In the affected version of the 1E Client, an ordinary user c…8.8
- CVE-2023-45161The 1E-Exchange-URLResponseTime instruction that is part of …7.2
- CVE-2023-45162Affected 1E Platform versions have a Blind SQL Injection vul…9.8
Are you affected by CVE-2023-45152?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
