Lif Auth Server is a server for validating logins, managing information, and account recovery for Lif Accounts. The issue relates to the `get_pfp` and `get_banner` routes on Auth Server. The issue is that there is no check to ensure that the file that Auth Server is receiving through these URLs is correct. This could allow an attacker access to files they shouldn't have access to. This issue has been patched in version 1.4.0.
References
Configurations
History
22 Jan 2024, 19:49
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/Lif-Platforms/Lif-Auth-Server/commit/c235bcc2ee65e4a0dfb10284cf2cbc750213efeb - Patch | |
References | () https://github.com/Lif-Platforms/Lif-Auth-Server/security/advisories/GHSA-3v77-pvqq-qg3f - Vendor Advisory | |
CPE | cpe:2.3:a:lifplatforms:lif_auth_server:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CWE | CWE-22 | |
First Time |
Lifplatforms lif Auth Server
Lifplatforms |
12 Jan 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-12 21:15
Updated : 2024-02-28 20:54
NVD link : CVE-2023-49801
Mitre link : CVE-2023-49801
CVE.ORG link : CVE-2023-49801
JSON object : View
Products Affected
lifplatforms
- lif_auth_server