Description
A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web API.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update LXCA to version 4.0 or later.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-38497 | A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web API. |
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-98715 |
|
History
Wed, 04 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-12-04T14:33:26.899Z
Reserved: 2023-06-05T19:15:31.605Z
Link: CVE-2023-34420
Updated: 2024-08-02T16:10:06.970Z
Status : Modified
Published: 2023-06-26T20:15:10.247
Modified: 2024-11-21T08:07:12.173
Link: CVE-2023-34420
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD