CVE-2023-49706
Defective request context handling in Self Service in LinOTP 3.x before 3.2.5 allows remote unauthenticated attackers to escalate privileges, thereby allowing them to act as and with the permissions of another user.
Does this matter?
Lower severity and a low EPSS score (0.61%). Track it; it rarely justifies an emergency change on its own.
Description
Defective request context handling in Self Service in LinOTP 3.x before 3.2.5 allows remote unauthenticated attackers to escalate privileges, thereby allowing them to act as and with the permissions of another user. Attackers must generate repeated API requests to trigger a race condition with concurrent user activity in the self-service portal.
- CVSS 3.1
- 6.8 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
- EPSS
- 0.61% probability · 48th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- linotp/linotp · linotp/virtual appliance
- Source
- cve@mitre.org
References
- https://linotp.org/CVE-2023-49706.txtVendor Advisory
- https://linotp.org/security-update-linotp3-selfservice.htmlVendor Advisory
- https://www.linotp.org/news.htmlVendor Advisory
- https://linotp.org/CVE-2023-49706.txtVendor Advisory
- https://linotp.org/security-update-linotp3-selfservice.htmlVendor Advisory
- https://www.linotp.org/news.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.