CVE-2023-28794Origin Validation Error in Client Connector

Severity
6.5MEDIUMNVD
CNA4.3
EPSS
0.1%
top 78.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 6

Description

Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Privilege Abuse. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5zscaler/client_connector< 1.3.1.6

🔴Vulnerability Details

2
CVEList
PAC Files Exposed to Internet Websites2023-11-06
GHSA
GHSA-jg7r-pc4g-p6vp: Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Privilege Abuse2023-11-06
CVE-2023-28794 — Origin Validation Error | cvebase