NA

CVE-2023-25573

Published: 09/03/2023 Updated: 15/03/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

metersphere is an open source continuous testing platform. In affected versions an improper access control vulnerability exists in `/api/jmeter/download/files`, which allows any user to download any file without authentication. This issue may expose all files available to the running process. This issue has been addressed in version 1.20.20 lts and 2.7.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

metersphere metersphere

Vendor Advisories

Check Point Reference: CPAI-2023-1467 Date Published: 25 Jan 2024 Severity: High ...

Github Repositories

CVE-2023-25573 - Metersphere < Arbitrary File Read

CVE-2023-25573-PoC CVE-2023-25573 - Metersphere &lt; Arbitrary File Read