CVE-2023-27001

An issue discovered in Egerie Risk Manager v4.0.5 allows attackers to bypass the signature mechanism and tamper with the values inside the JWT payload resulting in privilege escalation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:egerie:egerie:4.0.5:*:*:*:*:*:*:*

History

21 Nov 2024, 07:52

Type Values Removed Values Added
References () https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2023-27001.pdf - Exploit, Third Party Advisory () https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2023-27001.pdf - Exploit, Third Party Advisory

15 Feb 2024, 16:01

Type Values Removed Values Added
Summary
  • (es) Un problema descubierto en Egerie Risk Manager v4.0.5 permite a los atacantes eludir el mecanismo de firma y alterar los valores dentro de el payload de JWT, lo que resulta en una escalada de privilegios.
First Time Egerie
Egerie egerie
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:egerie:egerie:4.0.5:*:*:*:*:*:*:*
CWE NVD-CWE-Other
References () https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2023-27001.pdf - () https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2023-27001.pdf - Exploit, Third Party Advisory

08 Feb 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-08 22:15

Updated : 2024-11-21 07:52


NVD link : CVE-2023-27001

Mitre link : CVE-2023-27001

CVE.ORG link : CVE-2023-27001


JSON object : View

Products Affected

egerie

  • egerie