CVE-2023-50976

Redpanda before 23.1.21 and 23.2.x before 23.2.18 has missing authorization checks in the Transactions API.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redpanda:redpanda:*:*:*:*:*:*:*:*
cpe:2.3:a:redpanda:redpanda:*:*:*:*:*:*:*:*

History

22 Dec 2023, 21:23

Type Values Removed Values Added
CWE CWE-862
CPE cpe:2.3:a:redpanda:redpanda:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://github.com/redpanda-data/redpanda/pull/14969 - () https://github.com/redpanda-data/redpanda/pull/14969 - Issue Tracking, Patch
References () https://github.com/redpanda-data/redpanda/compare/v23.1.20...v23.1.21 - () https://github.com/redpanda-data/redpanda/compare/v23.1.20...v23.1.21 - Release Notes
References () https://github.com/redpanda-data/redpanda/pull/15060 - () https://github.com/redpanda-data/redpanda/pull/15060 - Issue Tracking, Patch
References () https://github.com/redpanda-data/redpanda/issues/15048 - () https://github.com/redpanda-data/redpanda/issues/15048 - Exploit, Issue Tracking
References () https://github.com/redpanda-data/redpanda/compare/v23.2.17...v23.2.18 - () https://github.com/redpanda-data/redpanda/compare/v23.2.17...v23.2.18 - Release Notes

18 Dec 2023, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-18 00:15

Updated : 2024-02-05 00:22


NVD link : CVE-2023-50976

Mitre link : CVE-2023-50976

CVE.ORG link : CVE-2023-50976


JSON object : View

Products Affected

redpanda

  • redpanda
CWE
CWE-862

Missing Authorization