CVE-2023-4456

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Aug 21, 2023
Updated: Nov 7, 2023
CWE ID 1220

Summary

CVE-2023-4456 is a newly discovered vulnerability affecting the openshift-logging LokiStack. The issue lies in the caching mechanism where the key used is only the token, which is overly permissive. Consequently, a user with a token valid for one specific action can perform other actions, as long as the authorization for the initial action remains cached. This vulnerability poses a significant risk to security, as it allows unintended access and escalation of privileges. It is recommended that users update their LokiStack installation to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share