CVE-2023-4320

An arithmetic overflow flaw was found in Satellite when creating a new personal access token. This flaw allows an attacker who uses this arithmetic overflow to create personal access tokens that are valid indefinitely, resulting in damage to the system's integrity.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:satellite:*:*:*:*:*:*:*:*

History

25 Apr 2024, 14:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:2010 -

29 Dec 2023, 22:45

Type Values Removed Values Added
First Time Redhat satellite
Redhat
Summary
  • (es) Se encontró una falla de desbordamiento aritmético en Satellite al crear un nuevo token de acceso personal. Esta falla permite a un atacante que utiliza este desbordamiento aritmético crear tokens de acceso personal que son válidos indefinidamente, lo que daña la integridad del sistema.
CPE cpe:2.3:a:redhat:satellite:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 6.0
v2 : unknown
v3 : 7.5
References () https://access.redhat.com/security/cve/CVE-2023-4320 - () https://access.redhat.com/security/cve/CVE-2023-4320 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2231814 - () https://bugzilla.redhat.com/show_bug.cgi?id=2231814 - Issue Tracking

18 Dec 2023, 15:04

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-18 14:15

Updated : 2024-04-25 14:15


NVD link : CVE-2023-4320

Mitre link : CVE-2023-4320

CVE.ORG link : CVE-2023-4320


JSON object : View

Products Affected

redhat

  • satellite
CWE
CWE-613

Insufficient Session Expiration