Vulnerability Description
CloudExplorer Lite is an open source cloud management platform. In CloudExplorer Lite prior to version 1.1.0 users organization/workspace permissions are not properly checked. This allows users to add themselves to any organization. This vulnerability has been fixed in v1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fit2Cloud | Cloudexplorer | < 1.1.0 |
Related Weaknesses (CWE)
References
- https://github.com/CloudExplorer-Dev/CloudExplorer-Lite/security/advisories/GHSAVendor Advisory
- https://github.com/CloudExplorer-Dev/CloudExplorer-Lite/security/advisories/GHSAVendor Advisory
- https://github.com/CloudExplorer-Dev/CloudExplorer-Lite/security/advisories/GHSAVendor Advisory
FAQ
What is CVE-2023-32311?
CVE-2023-32311 is a vulnerability with a CVSS score of 7.1 (HIGH). CloudExplorer Lite is an open source cloud management platform. In CloudExplorer Lite prior to version 1.1.0 users organization/workspace permissions are not properly checked. This allows users to add...
How severe is CVE-2023-32311?
CVE-2023-32311 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-32311?
Check the references section above for vendor advisories and patch information. Affected products include: Fit2Cloud Cloudexplorer.