Authenticated clients can read arbitrary files on the...
Low severity
Unreviewed
Published
Nov 1, 2023
to the GitHub Advisory Database
•
Updated Nov 8, 2023
Description
Published by the National Vulnerability Database
Nov 1, 2023
Published to the GitHub Advisory Database
Nov 1, 2023
Last updated
Nov 8, 2023
Authenticated clients can read arbitrary files on the MAIN Computer
system using the remote procedure call (RPC) of the InspectSetup
service endpoint. The low privilege client is then allowed to read arbitrary files that they do not have authorization to read.
References