Mage terminal user authentication not working properly
CVE-2023-31143

5.9MEDIUM

Key Information:

Vendor

Mage-ai

Status
Vendor
CVE Published:
9 May 2023

What is CVE-2023-31143?

A vulnerability exists in Mage AI's open-source data pipeline tool that allows unauthorized access to users who are not signed in or lack the necessary editor permissions. This affects versions from 0.8.34 up to 0.8.72, highlighting significant security risks for organizations using this data transformation tool. Users are encouraged to update to version 0.8.72 or later to mitigate this risk.

Affected Version(s)

mage-ai >= 0.8.34, < 0.8.72

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.