CVE-2023-28795Origin Validation Error in Client Connector

Severity
7.8HIGHNVD
EPSS
0.0%
top 92.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 23

Description

Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Inclusion of Code in Existing Process. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5zscaler/client_connector< 1.3.1.6

🔴Vulnerability Details

2
GHSA
GHSA-wwff-qqfj-cv2g: Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Inclusion of Code in Existing Process2023-10-23
CVEList
Client IPC validation bypass2023-10-23
CVE-2023-28795 — Origin Validation Error | cvebase