The vulnerability allows a remote authenticated attacker to read or update arbitrary content of the authentication database via a crafted HTTP request. By abusing this vulnerability it is possible to exfiltrate other users’ password hashes or update them with arbitrary values and access their accounts.
History

Tue, 17 Jun 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: bosch

Published: 2024-01-10T13:02:19.652Z

Updated: 2025-06-17T20:59:13.701Z

Reserved: 2023-11-13T13:44:23.705Z

Link: CVE-2023-48253

cve-icon Vulnrichment

Updated: 2024-08-02T21:23:39.464Z

cve-icon NVD

Status : Modified

Published: 2024-01-10T13:15:45.803

Modified: 2024-11-21T08:31:19.600

Link: CVE-2023-48253

cve-icon Redhat

No data.