Vulnerability Description
Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE: the vendor's position is that there is no security threat.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Plesk | Onyx | 17.8.11 |
Related Weaknesses (CWE)
References
- https://docs.aws.amazon.com/IAM/latest/UserGuide/security-creds.htmlNot Applicable
- https://talk.plesk.com/threads/why-in-plesk-firehouse-aws-keys-are-public.369925Vendor Advisory
- https://docs.aws.amazon.com/IAM/latest/UserGuide/security-creds.htmlNot Applicable
- https://talk.plesk.com/threads/why-in-plesk-firehouse-aws-keys-are-public.369925Vendor Advisory
FAQ
What is CVE-2023-43784?
CVE-2023-43784 is a vulnerability with a CVSS score of 7.5 (HIGH). Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE: the vendor's position is that there is no security threat.
How severe is CVE-2023-43784?
CVE-2023-43784 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-43784?
Check the references section above for vendor advisories and patch information. Affected products include: Plesk Onyx.