An authenticated administrator can upload a SAML configuration file with the wrong format, with the application not checking the correct file format. Every subsequent application request will return an error.
The whole application in rendered unusable until a console intervention.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://security.nozominetworks.com/NN-2023:7-01 |
History
Fri, 20 Sep 2024 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 20 Sep 2024 12:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-20 |
Fri, 20 Sep 2024 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-1286 |
MITRE
Status: PUBLISHED
Assigner: Nozomi
Published: 2023-08-09T09:12:24.994Z
Updated: 2024-09-20T12:09:31.800Z
Reserved: 2023-01-24T10:39:24.300Z
Link: CVE-2023-23903
Vulnrichment
Updated: 2024-08-02T10:42:26.840Z
NVD
Status : Modified
Published: 2023-08-09T10:15:09.687
Modified: 2024-11-21T07:47:04.113
Link: CVE-2023-23903
Redhat
No data.