9.8
CVSSv3

CVE-2023-51982

Published: 30/01/2024 Updated: 06/02/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After configuring password authentication and_ Local_ In the case of an address, identity authentication can be bypassed by setting the X-Real IP request header to a specific value and accessing the Admin UI directly using the default user identity.(github.com/crate/crate/issues/15231)

Vulnerable Product Search on Vulmon Subscribe to Product

cratedb cratedb 5.5.1