Exposure of Sensitive Information to an Unauthorized Actor
CVE-2023-20898
Summary
Git Providers can read from the wrong environment because they get the same cache directory base name in Salt masters versions prior to 3005.2, and 3006.x prior to 3006.2. Anything that uses Git Providers with different environments can get garbage data or the wrong data, which can lead to wrongful data disclosure, wrongful executions, data corruption, and/or crash.
- HIGH
- LOCAL
- HIGH
- CHANGED
- NONE
- LOW
- HIGH
- HIGH
CWE-200 - Information Exposure
An information exposure vulnerability is categorized as an information flow (IF) weakness, which can potentially allow unauthorized access to otherwise classified information in the application, such as confidential personal information (demographics, financials, health records, etc.), business secrets, and the application's internal environment.
References
Advisory Timeline
- Published