Information Disclosure Vulnerability in Gallagher Command Centre
CVE-2023-23584
4.3MEDIUM
What is CVE-2023-23584?
The Gallagher Command Centre REST API exhibits a response discrepancy that allows users with insufficient privileges to infer the existence of otherwise hidden items. This vulnerability could potentially enable unauthorized access to sensitive data, thereby posing a risk to users relying on the security of the system. Affected versions include Gallagher Command Centre 8.70 prior to vEL8.70.1787 (MR2), 8.60 prior to vEL8.60.2039 (MR4), and all versions of 8.50 and earlier. It is critical for users to apply the latest updates to mitigate this risk.
Affected Version(s)
Command Centre Server 0 <= 8.50
Command Centre Server 8.70 < 8.70.1787 (MR2)
Command Centre Server 8.60 < 8.60.2039 (MR4)