CVE-2023-0003
08.02.2023, 18:15
A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server.Enginsight
Vendor | Product | Version |
---|---|---|
paloaltonetworks | cortex_xsoar | 6.10.0 ≤ 𝑥 < 6.10.0.185964 |
paloaltonetworks | cortex_xsoar | 6.6.0:2585049 |
paloaltonetworks | cortex_xsoar | 6.6.0:2889656 |
paloaltonetworks | cortex_xsoar | 6.6.0:3049220 |
paloaltonetworks | cortex_xsoar | 6.6.0:3124193 |
paloaltonetworks | cortex_xsoar | 6.8.0:176620 |
paloaltonetworks | cortex_xsoar | 6.8.0:3261002 |
paloaltonetworks | cortex_xsoar | 6.9.0:130766 |
paloaltonetworks | cortex_xsoar | 6.9.0:177754 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-73 - External Control of File Name or PathThe software allows user input to control or influence paths or file names that are used in filesystem operations.
- CWE-610 - Externally Controlled Reference to a Resource in Another SphereThe product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
References