CVE-2023-0003

CVSS V2 None CVSS V3 None
Description
A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server.
Overview
  • CVE ID
  • CVE-2023-0003
  • Assigner
  • psirt@paloaltonetworks.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-02-08T18:15:11
  • Last Modified Date
  • 2023-02-18T20:45:39
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:paloaltonetworks:cortex_xsoar:*:*:*:*:*:*:*:* 1 OR 6.10.0 6.10.0.185964
cpe:2.3:a:paloaltonetworks:cortex_xsoar:6.6.0:2585049:*:*:*:*:*:* 1 OR
cpe:2.3:a:paloaltonetworks:cortex_xsoar:6.6.0:2889656:*:*:*:*:*:* 1 OR
cpe:2.3:a:paloaltonetworks:cortex_xsoar:6.6.0:3049220:*:*:*:*:*:* 1 OR
cpe:2.3:a:paloaltonetworks:cortex_xsoar:6.6.0:3124193:*:*:*:*:*:* 1 OR
cpe:2.3:a:paloaltonetworks:cortex_xsoar:6.8.0:176620:*:*:*:*:*:* 1 OR
cpe:2.3:a:paloaltonetworks:cortex_xsoar:6.8.0:3261002:*:*:*:*:*:* 1 OR
cpe:2.3:a:paloaltonetworks:cortex_xsoar:6.9.0:130766:*:*:*:*:*:* 1 OR
cpe:2.3:a:paloaltonetworks:cortex_xsoar:6.9.0:177754:*:*:*:*:*:* 1 OR
References
Reference URL Reference Tags
https://security.paloaltonetworks.com/CVE-2023-0003 Vendor Advisory
History
Created Old Value New Value Data Type Notes
2023-04-17 07:24:09 Added to TrackCVE
2023-04-17 07:24:11 Weakness Enumeration new