Vulnerability Description
Changes to user permissions in Portal for ArcGIS 10.9.1 and below are incompletely applied in specific use cases. This issue may allow users to access content that they are no longer privileged to access.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Esri | Portal For Arcgis | >= 10.7.1, <= 10.9.1 |
Related Weaknesses (CWE)
References
- https://support.esri.com/en-us/patches-updates/2023/portal-for-arcgis-security-2PatchRelease Notes
- https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/portal-forPatchVendor Advisory
- https://support.esri.com/en-us/patches-updates/2023/portal-for-arcgis-security-2PatchRelease Notes
- https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/portal-forPatchVendor Advisory
FAQ
What is CVE-2023-25834?
CVE-2023-25834 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Changes to user permissions in Portal for ArcGIS 10.9.1 and below are incompletely applied in specific use cases. This issue may allow users to access content that they are no longer privileged to acc...
How severe is CVE-2023-25834?
CVE-2023-25834 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-25834?
Check the references section above for vendor advisories and patch information. Affected products include: Esri Portal For Arcgis.