Command Injection in gosnowflake - CVE-2023-34231
Published: March 7, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists via single sign-on (SSO) browser URL authentication. A remote unauthenticated attacker can set up a malicious, publicly accessible server which responds to the SSO URL with an attack payload, trick the victim into visiting the maliciously crafted connection URL and execute arbitrary code on the target system.
Affected software
ObjectScale
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2023-34231
ObjectScale - update to 1.3.0
IBM Cloud Pak for Watson AIOps - update to 4.1.1