CVE Vulnerabilities

CVE-2023-50439

Published: Dec 13, 2023 | Modified: Dec 20, 2023
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission), ZED! for Windows before Q.2021.2 (ANSSI qualification submission), ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission), ZONECENTRAL for Windows before 2023.5, or ZEDMAIL for Windows before 2023.5 disclose the original path in which the containers were created, which allows an unauthenticated attacker to obtain some information regarding the context of use (project name, etc.).

Affected Software

Name Vendor Start Version End Version
Zed! Primx * q.2020.3 (excluding)
Zed! Primx 2023.0 (including) 2023.5 (excluding)
Zed! Primx q.2021.0 (including) q.2021.2 (excluding)
Zedmail Primx * 2023.5 (excluding)
Zonecentral Primx * q.2021.2 (excluding)
Zonecentral Primx 2023.0 (including) 2023.5 (excluding)

References