Exploiting Incorrectly Configured Access Control Security Levels
CVE-2023-22708
4.3MEDIUM
Summary
A vulnerability exists within the Kraken.io Image Optimizer that involves missing authorization, allowing attackers to exploit incorrectly configured access control security levels. This issue affects versions of Kraken.io Image Optimizer from n/a up to 2.6.7. Specifically, the lack of proper authorization mechanisms can lead to unauthorized access, potentially exposing sensitive information or allowing for unauthorized actions within the application. Users of the affected versions are advised to review their access control configurations and implement necessary mitigations to secure their environments.
Affected Version(s)
Kraken.io Image Optimizer <= 2.6.7
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
István Márton (Patchstack Alliance)