Missing authentication in the internal data streaming system in ProLion CryptoSpike 3.0.15P2 allows remote unauthenticated users to read potentially sensitive information and deny service to users by directly reading and writing data in Apache Kafka (as consumer and producer).
References
Link Resource
https://www.cvcn.gov.it/cvcn/cve/CVE-2023-36648 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-12-12T00:00:00

Updated: 2023-12-12T00:10:07.936373

Reserved: 2023-06-25T00:00:00


Link: CVE-2023-36648

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-12-12T01:15:10.067

Modified: 2023-12-13T23:38:17.737


Link: CVE-2023-36648

JSON object: View

cve-icon Redhat Information

No data.

CWE