Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate other users in web management and the REST API by reading JWT tokens from logs (as a Granafa authenticated user) or from the Loki REST API without authentication.
References
Link Resource
https://www.cvcn.gov.it/cvcn/cve/CVE-2023-36649 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-12-12T00:00:00

Updated: 2023-12-12T00:15:28.424844

Reserved: 2023-06-25T00:00:00


Link: CVE-2023-36649

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-12-12T01:15:10.123

Modified: 2023-12-14T15:34:02.853


Link: CVE-2023-36649

JSON object: View

cve-icon Redhat Information

No data.

CWE