SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-43661

Prior to the 2.4 branch, a template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version.

HIGH 8.8EPSS 46.9%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 46.9%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Cachet, the open-source status page system. Prior to the 2.4 branch, a template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Commit 6fb043e109d2a262ce3974e863c54e9e5f5e0587 of the 2.4 branch contains a patch for this issue.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
46.90% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-94, CWE-74
Affected
all-three/cachet
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.