CVE-2023-4664
published 2023-09-15CVE-2023-4664: Incorrect Default Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation. This issue affects Saphira Connect: before 9.
PriorityP350high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.81%
53.0th percentile
Incorrect Default Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation.
This issue affects Saphira Connect: before 9.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | connect | < 9.0 | 9.0 |
| saphira | saphira_connect | < 9 | 9 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5qrf-4c4q-429h: Incorrect Default Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation
ghsa_unreviewed·2023-09-15
CVE-2023-4664 [HIGH] CWE-276 GHSA-5qrf-4c4q-429h: Incorrect Default Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation
Incorrect Default Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation.This issue affects Saphira Connect: before 9.
GHSA
apollo-portal has potential CSRF issue
ghsa·2023-02-22
CVE-2023-25569 [MEDIUM] CWE-352 apollo-portal has potential CSRF issue
apollo-portal has potential CSRF issue
### Impact
A low-privileged user can create a special web page. If an authenticated portal admin visits this page, the page can silently send a request to assign new roles for that user without any confirmation from the Portal admin.
### Patches
Cookie SameSite strategy was set to Lax in #4664 and was released in [v2.1.0](https://github.com/apolloconfig/apollo/releases/tag/v2.1.0).
### Workarounds
To fix the potential issue without upgrading, simply follow the advice that does not visit unknown source pages.
### References
[Apollo Security Guidence](https://www.apolloconfig.com/#/en/usage/apollo-user-guide?id=_71-security-related)
### For more information
If you have any questions or comments about this advisory:
* Open an issue in [issue](https:
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-09-15
Published