CVE-2023-22644
JWT token compromise can allow malicious actions including Remote Code Execution (RCE)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An Innsertion of Sensitive Information into Log File vulnerability in SUSE SUSE Manager Server Module 4.2 spacewalk-java, SUSE SUSE Manager Server Module 4.3 spacewalk-java causes sensitive information to be logged.
This issue affects SUSE Manager Server Module 4.2: before 4.2.50-150300.3.66.5; SUSE Manager Server Module 4.3: before 4.3.58-150400.3.46.4.
Una vulnerabilidad de Inserción de Información Sensible en un Archivo de Registro en SUSE SUSE Manager Server Module 4.2 spacewalk-java, SUSE SUSE Manager Server Module 4.3 spacewalk-java provoca que se registre información sensible. Este problema afecta al módulo SUSE Manager Server 4.2: anterior a 4.2.50-150300.3.66.5; Módulo de servidor SUSE Manager 4.3: anterior a 4.3.58-150400.3.46.4.
A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-01-05 CVE Reserved
- 2023-09-20 CVE Published
- 2023-09-22 EPSS Updated
- 2024-10-15 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-532: Insertion of Sensitive Information into Log File
- CWE-1270: Generation of Incorrect Security Tokens
CAPEC
References (3)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Suse Search vendor "Suse" | Manager Server Search vendor "Suse" for product "Manager Server" | >= 4.2 < 4.2.50-150300.3.66.5 Search vendor "Suse" for product "Manager Server" and version " >= 4.2 < 4.2.50-150300.3.66.5" | - |
Affected
| ||||||
Suse Search vendor "Suse" | Manager Server Search vendor "Suse" for product "Manager Server" | >= 4.3 < 4.3.58-150400.3.46.4 Search vendor "Suse" for product "Manager Server" and version " >= 4.3 < 4.3.58-150400.3.46.4" | - |
Affected
|