CVE-2023-23849

Versions of Coverity Connect prior to 2022.12.0 are vulnerable to an unauthenticated Cross-Site Scripting vulnerability. Any web service hosted on the same sub domain can set a cookie for the whole subdomain which can be used to bypass other mitigations in place for malicious purposes. CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/RL:O/RC:C
Configurations

Configuration 1 (hide)

cpe:2.3:a:synopsys:coverity:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:46

Type Values Removed Values Added
References () https://community.synopsys.com/s/article/SIG-Product-Security-Advisory-CVE-2023-23849-affecting-Coverity - Vendor Advisory () https://community.synopsys.com/s/article/SIG-Product-Security-Advisory-CVE-2023-23849-affecting-Coverity - Vendor Advisory
Summary
  • (es) Las versiones de Coverity Connect anteriores a 2022.12.0 se ven afectadas por una vulnerabilidad de cross-site scripting no autenticadas. Cualquier servicio web alojado en el mismo subdominio puede configurar una cookie para todo el subdominio que puede usarse para evitar otras mitigaciones implementadas con fines maliciosos. CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/RL:O/RC:C

Information

Published : 2023-02-06 23:15

Updated : 2024-11-21 07:46


NVD link : CVE-2023-23849

Mitre link : CVE-2023-23849

CVE.ORG link : CVE-2023-23849


JSON object : View

Products Affected

synopsys

  • coverity
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')