CVE-2023-2227: Improper Authorization in modoboa
(updated )
In modoboa prior to 2.1.0, sending a GET request to the endpoint /api/v2/parameters/core/
returns sensitive information without any authentication or authorization.
References
- github.com/advisories/GHSA-67mg-gm8m-ph5r
- github.com/modoboa/modoboa
- github.com/modoboa/modoboa/commit/7bcd3f6eb264d4e3e01071c97c2bac51cdd6fe97
- github.com/pypa/advisory-database/tree/main/vulns/modoboa/PYSEC-2023-35.yaml
- huntr.dev/bounties/351f9055-2008-4af0-b820-01ff66678bf3
- nvd.nist.gov/vuln/detail/CVE-2023-2227
Detect and mitigate CVE-2023-2227 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →