Unsafe deserialization of untrusted JSON allows execution of arbitrary code on affected releases of the Illumio PCE. Authentication to the API is required to exploit this vulnerability. The flaw exists within the network_traffic API endpoint. An attacker can leverage this vulnerability to execute code in the context of the PCE’s operating system user.
References
Link | Resource |
---|---|
https://docs.illumio.com/Guides/security-advisories/september-2023/cve-2023-5183.htm | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: Illumio
Published: 2023-09-26T21:29:36.575Z
Updated: 2023-09-26T23:41:08.564Z
Reserved: 2023-09-25T18:22:12.952Z
Link: CVE-2023-5183
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-09-27T15:19:42.873
Modified: 2023-10-02T19:22:03.777
Link: CVE-2023-5183
JSON object: View
Redhat Information
No data.
CWE