Information disclosure in Omniverse Workstation Launcher - CVE-2023-25524

 

Information disclosure in Omniverse Workstation Launcher - CVE-2023-25524

Published: August 4, 2023


Vulnerability identifier: #VU78940
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-25524
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to an error in the authentication flow, where a user’s access token is displayed in the browser user's address bar. A remote attacker can obtain the token by various means (e.g. via HTTP Referer header) and impersonate the victim to access launcher resources.


Affected software

Omniverse Workstation Launcher

How to mitigate CVE-2023-25524

Install updates from vendor's website.

Omniverse Workstation Launcher - update to 1.8.11

External References

Related Security Bulletins