Vulnerability Description
Lif Auth Server is a server for validating logins, managing information, and account recovery for Lif Accounts. The issue relates to the `get_pfp` and `get_banner` routes on Auth Server. The issue is that there is no check to ensure that the file that Auth Server is receiving through these URLs is correct. This could allow an attacker access to files they shouldn't have access to. This issue has been patched in version 1.4.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lifplatforms | Lif Auth Server | < 1.4.0 |
Related Weaknesses (CWE)
References
- https://github.com/Lif-Platforms/Lif-Auth-Server/commit/c235bcc2ee65e4a0dfb10284Patch
- https://github.com/Lif-Platforms/Lif-Auth-Server/security/advisories/GHSA-3v77-pVendor Advisory
- https://github.com/Lif-Platforms/Lif-Auth-Server/commit/c235bcc2ee65e4a0dfb10284Patch
- https://github.com/Lif-Platforms/Lif-Auth-Server/security/advisories/GHSA-3v77-pVendor Advisory
FAQ
What is CVE-2023-49801?
CVE-2023-49801 is a vulnerability with a CVSS score of 4.2 (MEDIUM). Lif Auth Server is a server for validating logins, managing information, and account recovery for Lif Accounts. The issue relates to the `get_pfp` and `get_banner` routes on Auth Server. The issue is ...
How severe is CVE-2023-49801?
CVE-2023-49801 has been rated MEDIUM with a CVSS base score of 4.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-49801?
Check the references section above for vendor advisories and patch information. Affected products include: Lifplatforms Lif Auth Server.