CVE-2023-27001

An issue discovered in Egerie Risk Manager v4.0.5 allows attackers to bypass the signature mechanism and tamper with the values inside the JWT payload resulting in privilege escalation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:egerie:egerie:4.0.5:*:*:*:*:*:*:*

History

15 Feb 2024, 16:01

Type Values Removed Values Added
First Time Egerie
Egerie egerie
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
References () https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2023-27001.pdf - () https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2023-27001.pdf - Exploit, Third Party Advisory
CPE cpe:2.3:a:egerie:egerie:4.0.5:*:*:*:*:*:*:*
CWE NVD-CWE-Other

08 Feb 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-08 22:15

Updated : 2025-06-17 14:15


NVD link : CVE-2023-27001

Mitre link : CVE-2023-27001


JSON object : View

Products Affected

egerie

  • egerie