跳转到帖子

Qlik Sense Enterprise: CVE-2023-41265: HTTP Tunneling vulnerability in Qlik Sense Enterprise for Windows

recommended_posts

发布于
  • Members

Qlik Sense Enterprise: CVE-2023-41265: HTTP Tunneling vulnerability in Qlik Sense Enterprise for Windows

Severity
9
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:N)
Published
08/29/2023
Created
03/27/2024
Added
03/26/2024
Modified
03/27/2024

Description

Due to improper validation of HTTP Headers a remote attacker is able to elevate their privilege by tunnelling HTTP requests, allowing them to execute HTTP requests on the backend server hosting the repository application.

Solution(s)

  • qlik-sense-enterprise-upgrade-latest

References

  • https://attackerkb.com/topics/cve-2023-41265
  • CVE - 2023-41265
  • https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/ta-p/2110801
  • 查看数 701
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…