CVE-2023-26431
CVSS V2 None
CVSS V3 None
Description
IPv4-mapped IPv6 addresses did not get recognized as "local" by the code and a connection attempt is made. Attackers with access to user accounts could use this to bypass existing deny-list functionality and trigger requests to restricted network infrastructure to gain insight about topology and running services. We now respect possible IPV4-mapped IPv6 addresses when checking if contained in a deny-list. No publicly available exploits are known.
Overview
- CVE ID
- CVE-2023-26431
- Assigner
- OX
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-06-20T07:51:43.448Z
- Last Modified Date
- 2024-01-12T07:14:23.981Z
Weakness Enumerations
References
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-26431 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-26431 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-24 23:15:45 | Added to TrackCVE |