8.8
CVE-2023-6239
- EPSS 0.06%
- Veröffentlicht 28.11.2023 14:15:07
- Zuletzt bearbeitet 23.02.2026 09:16:16
- Quelle security@m-files.com
- CVE-Watchlists
- Unerledigt
Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specific configuration of metadata-driven permissions in M-Files Server versions 23.9, 23.10, and 23.11 before 23.11.13168.7, potentially enabling unauthorized access to the object.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
M-files ≫ M-files Server Version >= 23.11 < 23.11.13168.7
M-files ≫ M-files Server Version23.9
M-files ≫ M-files Server Version23.10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.181 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| security@m-files.com | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
|
CWE-281 Improper Preservation of Permissions
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.