Netwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on deployment endpoints, leading to privilege escalation. This only occurs if the configuration omits the required restSettings.AuthorizedClientId and restSettings.AuthorizedSecret fields (for the POST /api/Deployment/ExportConfiguration and POST /api/Deployment endpoints).
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-11-28T00:00:00

Updated: 2023-11-28T17:07:19.717247

Reserved: 2023-08-25T00:00:00


Link: CVE-2023-41264

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-11-28T17:15:07.857

Modified: 2023-12-04T19:17:54.180


Link: CVE-2023-41264

JSON object: View

cve-icon Redhat Information

No data.

CWE