Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-23568 | An authenticated attacker can leverage an exposed resource.db() accessor method to smuggle Python method calls via a Jinja template, which can lead to code execution. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version of InsightCloudSec. |
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2025-02-26T16:39:23.347Z
Reserved: 2023-03-09T22:23:16.140Z
Link: CVE-2023-1306
Updated: 2024-08-02T05:41:00.061Z
Status : Modified
Published: 2023-03-21T17:15:11.797
Modified: 2025-02-26T17:15:15.517
Link: CVE-2023-1306
No data.
OpenCVE Enrichment
No data.
EUVD