Unsafe deserialization of untrusted JSON allows execution of arbitrary code on affected releases of the Illumio PCE. Authentication to the API is required to exploit this vulnerability. The flaw exists within the network_traffic API endpoint. An attacker can leverage this vulnerability to execute code in the context of the PCE’s operating system user.
Metrics
Affected Vendors & Products
References
History
Tue, 24 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: Illumio
Published: 2023-09-26T21:29:36.575Z
Updated: 2024-09-24T13:43:17.802Z
Reserved: 2023-09-25T18:22:12.952Z
Link: CVE-2023-5183

Updated: 2024-08-02T07:52:07.639Z

Status : Modified
Published: 2023-09-27T15:19:42.873
Modified: 2024-11-21T08:41:15.240
Link: CVE-2023-5183

No data.