CVE-2023-49706
Last modified
CVE-2023-49706 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Defective request context handling in Self Service in LinOTP 3.x before 3.2.5 allows remote unauthenticated attackers to escalate privileges, thereby allowing them to act as and with the permissions of another user. Attackers must generate repeated API requests to trigger a race condition with concurrent user activity in the self-service portal.. EPSS estimates a 0.62% chance of exploitation in the next 30 days.
Description
Defective request context handling in Self Service in LinOTP 3.x before 3.2.5 allows remote unauthenticated attackers to escalate privileges, thereby allowing them to act as and with the permissions of another user. Attackers must generate repeated API requests to trigger a race condition with concurrent user activity in the self-service portal.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linotp | Linotp | >= 3.0.0, <= 3.2.4 |
| Linotp | Virtual Appliance | >= 3.0.0, <= 3.2.4 |
References
- https://linotp.org/CVE-2023-49706.txtVendor Advisory
- https://linotp.org/security-update-linotp3-selfservice.htmlVendor Advisory
- https://www.linotp.org/news.htmlVendor Advisory
- https://linotp.org/CVE-2023-49706.txtVendor Advisory
- https://linotp.org/security-update-linotp3-selfservice.htmlVendor Advisory
- https://www.linotp.org/news.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-49706?
How severe is CVE-2023-49706?
How do I fix CVE-2023-49706?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-49694 A low-privileged OS user with access to a Windows host wh…7.8
- CVE-2023-49695OS command injection vulnerability in WRC-X3000GSN v1.0.2, W…6.8
- CVE-2023-49699Memory Corruption in IMS while calling VoLTE Streamingmedia …7.8
- CVE-2023-4970The PubyDoc WordPress plugin through 2.0.6 does not sanitise…4.8
- CVE-2023-49700Security best practices violations, a string operation in St…7.5
- CVE-2023-49701Memory Corruption in SIM management while USIMPhase2init 9.8
- CVE-2023-49707SQLi vulnerability in S5 Register module for Joomla.9.8
- CVE-2023-49708SQLi vulnerability in Starshop component for Joomla.9.8
- CVE-2023-4971The Weaver Xtreme Theme Support WordPress plugin before 6.3.…7.2
- CVE-2023-49710Rejected reason: This is unused.
- CVE-2023-49712Rejected reason: This is unused.
- CVE-2023-49713Denial-of-service (DoS) vulnerability exists in NetBIOS serv…7.5
Are you affected by CVE-2023-49706?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
