CVE Vulnerabilities

CVE-2023-27372

Published: Feb 28, 2023 | Modified: Mar 11, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.

Affected Software

NameVendorStart VersionEnd Version
SpipSpip*3.2.18 (excluding)
SpipSpip4.0.0 (including)4.0.10 (excluding)
SpipSpip4.1.0 (including)4.1.8 (excluding)
SpipSpip4.2.0 (including)4.2.0 (including)
SpipSpip4.2.0-alpha (including)4.2.0-alpha (including)
SpipSpip4.2.0-alpha2 (including)4.2.0-alpha2 (including)
SpipUbuntubionic*
SpipUbuntuesm-apps/bionic*
SpipUbuntuesm-apps/focal*
SpipUbuntuesm-apps/jammy*
SpipUbuntuesm-apps/xenial*
SpipUbuntufocal*
SpipUbuntujammy*
SpipUbuntukinetic*
SpipUbuntulunar*
SpipUbuntumantic*
SpipUbuntutrusty*
SpipUbuntuupstream*
SpipUbuntuxenial*

References