SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-25834

This issue may allow users to access content that they are no longer privileged to access.

MEDIUM 5.4EPSS 0.32%

Does this matter?

Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.

Description

Changes to user permissions in Portal for ArcGIS 10.9.1 and below are incompletely applied in specific use cases. This issue may allow users to access content that they are no longer privileged to access.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS
0.32% probability · 25th percentile
CISA KEV
Not listed
Weakness
CWE-269
Affected
esri/portal for arcgis
Source
psirt@esri.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.