CVE-2023-27001

An issue discovered in Egerie Risk Manager v4.0.5 allows attackers to bypass the signature mechanism and tamper with the values inside the JWT payload resulting in privilege escalation.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:egerie:egerie:4.0.5:*:*:*:*:*:*:*

History

15 Feb 2024, 16:01

Type Values Removed Values Added
References () https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2023-27001.pdf - () https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2023-27001.pdf - Exploit, Third Party Advisory
CPE cpe:2.3:a:egerie:egerie:4.0.5:*:*:*:*:*:*:*
CWE NVD-CWE-Other
First Time Egerie egerie
Egerie
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

08 Feb 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-08 22:15

Updated : 2024-02-28 20:54


NVD link : CVE-2023-27001

Mitre link : CVE-2023-27001

CVE.ORG link : CVE-2023-27001


JSON object : View

Products Affected

egerie

  • egerie