CVE-2023-32360
published 2023-06-23CVE-2023-32360: An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4…
PriorityP426medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.35%
27.2th percentile
An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An unauthenticated user may be able to access recently printed documents.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 2.3.3op2-3+deb11u4 | 2.3.3op2-3+deb11u4 |
| apple | cups | >= 0 < 2.4.2-3+deb12u2 | 2.4.2-3+deb12u2 |
| apple | cups | >= 0 < 2.4.2-6 | 2.4.2-6 |
| apple | cups | >= 0 < 2.4.2-6 | 2.4.2-6 |
| apple | macos | >= 11.0 < 11.7.7 | 11.7.7 |
| apple | macos | >= 12.0.0 < 12.6.6 | 12.6.6 |
| apple | macos | >= 13.0 < 13.4 | 13.4 |
| apple | macos | >= unspecified < 13.4 | 13.4 |
| apple | macos | >= unspecified < 12.6 | 12.6 |
| apple | macos | >= unspecified < 11.7 | 11.7 |
| apple | macos_big_sur | — | — |
| apple | macos_monterey | — | — |
| apple | macos_ventura | — | — |
| debian | cups | < cups 2.4.2-3+deb12u2 (bookworm) | cups 2.4.2-3+deb12u2 (bookworm) |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
CUPS vulnerability
vendor_ubuntu·2023-09-26
CVE-2023-32360 CUPS vulnerability
Title: CUPS vulnerability
Summary: CUPS could be made to expose sensitive information.
USN-6361-1 fixed a vulnerability in CUPS. This update provides the
corresponding updates for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that CUPS incorrectly authenticated certain remote
requests. A remote attacker could possibly use this issue to obtain
recently printed documents.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
CUPS vulnerability
vendor_ubuntu·2023-09-12
CVE-2023-32360 CUPS vulnerability
Title: CUPS vulnerability
Summary: CUPS could be made to expose sensitive information.
It was discovered that CUPS incorrectly authenticated certain remote
requests. A remote attacker could possibly use this issue to obtain
recently printed documents.
Instructions: In general, a standard system update will make all the necessary changes.
Apple
CVE-2023-32360: macOS Monterey 12.6.6
vendor_apple·2023-05-18·CVSS 5.5
CVE-2023-32360 [MEDIUM] CVE-2023-32360: macOS Monterey 12.6.6
Apple Security Update: About the security content of macOS Monterey 12.6.6
Product: macOS Monterey
Version: 12.6.6
CVE: CVE-2023-32360
Component: CUPS
Impact: An unauthenticated user may be able to access recently printed documents
Description: An authentication issue was addressed with improved state management.
Apple
CVE-2023-32360: macOS Ventura 13.4
vendor_apple·2023-05-18·CVSS 5.5
CVE-2023-32360 [MEDIUM] CVE-2023-32360: macOS Ventura 13.4
Apple Security Update: About the security content of macOS Ventura 13.4
Product: macOS Ventura
Version: 13.4
CVE: CVE-2023-32360
Component: CUPS
Impact: An unauthenticated user may be able to access recently printed documents
Description: An authentication issue was addressed with improved state management.
Apple
CVE-2023-32360: macOS Big Sur 11.7.7
vendor_apple·2023-05-18·CVSS 5.5
CVE-2023-32360 [MEDIUM] CVE-2023-32360: macOS Big Sur 11.7.7
Apple Security Update: About the security content of macOS Big Sur 11.7.7
Product: macOS Big Sur
Version: 11.7.7
CVE: CVE-2023-32360
Component: CUPS
Impact: An unauthenticated user may be able to access recently printed documents
Description: An authentication issue was addressed with improved state management.
Debian
CVE-2023-32360: cups - An authentication issue was addressed with improved state management. This issue...
vendor_debian·2023·CVSS 5.5
CVE-2023-32360 [MEDIUM] CVE-2023-32360: cups - An authentication issue was addressed with improved state management. This issue...
An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An unauthenticated user may be able to access recently printed documents.
Scope: local
bookworm: resolved (fixed in 2.4.2-3+deb12u2)
bullseye: resolved (fixed in 2.3.3op2-3+deb11u4)
forky: resolved (fixed in 2.4.2-6)
sid: resolved (fixed in 2.4.2-6)
trixie: resolved (fixed in 2.4.2-6)
Red Hat
cups: Information leak through Cups-Get-Document operation
vendor_redhat·2022-12-06·CVSS 5.5
CVE-2023-32360 [MEDIUM] CWE-200 cups: Information leak through Cups-Get-Document operation
cups: Information leak through Cups-Get-Document operation
An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An unauthenticated user may be able to access recently printed documents.
A vulnerability was found in OpenPrinting CUPS. Unauthorized users are permitted to fetch documents over local or remote networks, leading to confidentiality breach.
Statement: This vulnerability is classified as important according to Red Hat's Severity Rating Classification, as unauthorized users are permitted to fetch documents over local or remote networks, leading to confidentiality breach.
https://access.redhat.com/security/updates/classification
Mitigation: The user can either set 'PreserveJob
GHSA
GHSA-cx3f-98jp-8mqj: An authentication issue was addressed with improved state management
ghsa_unreviewed·2023-06-23
CVE-2023-32360 [MEDIUM] CWE-125 GHSA-cx3f-98jp-8mqj: An authentication issue was addressed with improved state management
An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.4, macOS Big Sur 11.7.7, macOS Monterey 12.6.6. An unauthenticated user may be able to access recently printed documents
OSV
CVE-2023-32360: An authentication issue was addressed with improved state management
osv·2023-06-23·CVSS 5.5
CVE-2023-32360 [MEDIUM] CVE-2023-32360: An authentication issue was addressed with improved state management
An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An unauthenticated user may be able to access recently printed documents.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2023/09/msg00041.htmlhttps://support.apple.com/en-us/HT213758https://support.apple.com/en-us/HT213759https://support.apple.com/en-us/HT213760https://lists.debian.org/debian-lts-announce/2023/09/msg00041.htmlhttps://support.apple.com/en-us/HT213758https://support.apple.com/en-us/HT213759https://support.apple.com/en-us/HT213760
2023-06-23
Published