CVE Vulnerabilities

CVE-2023-4560

Improper Authorization of Index Containing Sensitive Information

Published: Aug 28, 2023 | Modified: Aug 29, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper Authorization of Index Containing Sensitive Information in GitHub repository omeka/omeka-s prior to 4.0.4.

Weakness

The product creates a search index of private or sensitive documents, but it does not properly limit index access to actors who are authorized to see the original information.

Affected Software

Name Vendor Start Version End Version
Omeka_s Omeka * 4.0.4 (excluding)

References