Improper Authentication in OpenSearch - CVE-2023-23612
Published: December 12, 2024
Vulnerability identifier: #VU101750
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-23612
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote privileged user to bypass authentication process.
The vulnerability exists due to a flaw in with whitespace in JWT roles. A remote privileged user can bypass authentication process and gain unauthorized access to the application.
Affected software
OpenSearch
Cognos Dashboards on Cloud Pak for Data
Cognos Dashboards on Cloud Pak for Data
How to mitigate CVE-2023-23612
Install updates from vendor's website.
OpenSearch - addressed in versions 1.3.8, 2.5.0
Cognos Dashboards on Cloud Pak for Data - update to 5.1
Cognos Dashboards on Cloud Pak for Data - update to 5.1