CVE-2023-5457

A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web application (due to the “debug” configuration parameter set to “True”) allows a remote unauthenticated attacker to access critical information and have other unspecified impacts to the confidentiality, integrity, and availability of the application. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ailux:imx6:*:*:*:*:*:*:*:*

History

09 Apr 2025, 20:34

Type Values Removed Values Added
First Time Ailux
Ailux imx6
CWE NVD-CWE-Other
CPE cpe:2.3:a:ailux:imx6:*:*:*:*:*:*:*:*
References () https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2023-5457 - () https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2023-5457 - Third Party Advisory

21 Nov 2024, 08:41

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad CWE-1269 de "Producto lanzado en configuración sin lanzamiento" en el framework web Django utilizado por la aplicación web (debido al parámetro de configuración "depuración" establecido en "Verdadero") permite que un atacante remoto no autenticado acceda a información crítica y tenga otros impactos no especificados a la confidencialidad, integridad y disponibilidad de la aplicación. Este problema afecta: Paquete AiLux imx6 inferior a la versión imx6_1.0.7-2.
References () https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2023-5457 - () https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2023-5457 -

05 Mar 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-05 12:15

Updated : 2025-04-09 20:34


NVD link : CVE-2023-5457

Mitre link : CVE-2023-5457

CVE.ORG link : CVE-2023-5457


JSON object : View

Products Affected

ailux

  • imx6
CWE
CWE-1269

Product Released in Non-Release Configuration

NVD-CWE-Other