CVE-2023-46125
Last modified
CVE-2023-46125 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcement of privacy regulations in code. The Fides webserver API allows users to retrieve its configuration using the `GET api/v1/config` endpoint. EPSS estimates a 0.72% chance of exploitation in the next 30 days.
Description
Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcement of privacy regulations in code. The Fides webserver API allows users to retrieve its configuration using the `GET api/v1/config` endpoint. The configuration data is filtered to suppress most sensitive configuration information before it is returned to the user, but even the filtered data contains information about the internals and the backend infrastructure, such as various settings, servers’ addresses and ports and database username. This information is useful for administrative users as well as attackers, thus it should not be revealed to low-privileged users. This vulnerability allows Admin UI users with roles lower than the owner role e.g. the viewer role to retrieve the config information using the API. The vulnerability has been patched in Fides version `2.22.1`.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ethyca | Fides | < 2.22.1 |
References
- https://github.com/ethyca/fides/releases/tag/2.22.1Release Notes
- https://github.com/ethyca/fides/security/advisories/GHSA-rjxg-rpg3-9r89Third Party Advisory
- https://github.com/ethyca/fides/releases/tag/2.22.1Release Notes
- https://github.com/ethyca/fides/security/advisories/GHSA-rjxg-rpg3-9r89Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-46125?
How severe is CVE-2023-46125?
How do I fix CVE-2023-46125?
Are you affected by CVE-2023-46125?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
