GBrowse accepts files with any formats uploaded and places them in the area accessible through unauthenticated web requests. Therefore, anyone who can upload files through the product may execute arbitrary code on the server.
History

Wed, 23 Oct 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2023-07-25T05:01:48.955Z

Updated: 2024-10-23T19:13:27.167Z

Reserved: 2023-05-11T04:09:45.896Z

Link: CVE-2023-32637

cve-icon Vulnrichment

Updated: 2024-08-02T15:25:36.265Z

cve-icon NVD

Status : Modified

Published: 2023-07-25T06:15:10.893

Modified: 2024-11-21T08:03:44.923

Link: CVE-2023-32637

cve-icon Redhat

No data.