CVE-2023-6336

Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows User-Controlled Filename.This issue affects Workforce Access: before 8.7.
References
Link Resource
https://www.hypr.com/security-advisories Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:hypr:workforce_access:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

History

23 Jan 2024, 16:25

Type Values Removed Values Added
First Time Hypr workforce Access
Apple macos
Hypr
Apple
CPE cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:a:hypr:workforce_access:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 7.2
v2 : unknown
v3 : 7.8
References () https://www.hypr.com/security-advisories - () https://www.hypr.com/security-advisories - Vendor Advisory
Summary
  • (es) La vulnerabilidad de resolución de enlace incorrecta antes del acceso al archivo ("Link Following") en HYPR Workforce Access en MacOS permite el nombre de archivo controlado por el usuario. Este problema afecta a Workforce Access: antes de 8.7.

16 Jan 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-16 20:15

Updated : 2024-01-23 16:25


NVD link : CVE-2023-6336

Mitre link : CVE-2023-6336

CVE.ORG link : CVE-2023-6336


JSON object : View

Products Affected

hypr

  • workforce_access

apple

  • macos
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')