CVE Vulnerabilities

CVE-2023-50439

Published: Dec 13, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission), ZED! for Windows before Q.2021.2 (ANSSI qualification submission), ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission), ZONECENTRAL for Windows before 2023.5, or ZEDMAIL for Windows before 2023.5 disclose the original path in which the containers were created, which allows an unauthenticated attacker to obtain some information regarding the context of use (project name, etc.).

Affected Software

NameVendorStart VersionEnd Version
Zed!Primx*q.2020.3 (excluding)
Zed!Primx2023.0 (including)2023.5 (excluding)
Zed!Primxq.2021.0 (including)q.2021.2 (excluding)
ZedmailPrimx*2023.5 (excluding)
ZonecentralPrimx*q.2021.2 (excluding)
ZonecentralPrimx2023.0 (including)2023.5 (excluding)

References