api/auth.go in Ansible Semaphore before 2.8.89 mishandles authentication.
References
Configurations
History
23 Mar 2023, 14:04
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://github.com/ansible-semaphore/semaphore/releases/tag/v2.8.89 - Release Notes | |
References | (MISC) https://github.com/ansible-semaphore/semaphore/commit/3e4a62b7f2b1ef0660c9fb839818a53c80a5a8b1 - Patch | |
CWE | CWE-287 | |
CPE | cpe:2.3:a:ansible-semaphore:ansible_semaphore:*:*:*:*:*:ansible:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
20 Mar 2023, 02:46
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-03-18 21:15
Updated : 2024-02-04 23:37
NVD link : CVE-2023-28609
Mitre link : CVE-2023-28609
CVE.ORG link : CVE-2023-28609
JSON object : View
Products Affected
ansible-semaphore
- ansible_semaphore
CWE
CWE-287
Improper Authentication