Vulnerability Description
An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to infer the presence of items that would not otherwise be viewable. This issue affects: Gallagher Command Centre 8.70 prior to vEL8.70.1787 (MR2), 8.60 prior to vEL8.60.2039 (MR4), all version of 8.50 and prior.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gallagher | Command Centre | <= 8.50 |
Related Weaknesses (CWE)
References
- https://security.gallagher.com/Security-Advisories/CVE-2023-23584Vendor Advisory
- https://security.gallagher.com/Security-Advisories/CVE-2023-23584Vendor Advisory
FAQ
What is CVE-2023-23584?
CVE-2023-23584 is a vulnerability with a CVSS score of 4.3 (MEDIUM). An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to infer the presence of items that would not otherwise be viewable. This issue a...
How severe is CVE-2023-23584?
CVE-2023-23584 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-23584?
Check the references section above for vendor advisories and patch information. Affected products include: Gallagher Command Centre.