CVE-2023-33740

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published May 30, 2023
Updated: Jan 13, 2025
CWE ID 346

Summary

CVE-2023-33740 is a newly discovered vulnerability affecting luowice version 3.5.18. This issue involves incorrect access control, which allows unauthorized users to gain access to cloud source code information. Attackers can exploit this vulnerability by manipulating the Verify parameter in a warning message. The consequence of this exploit is the exposure of sensitive data, potentially leading to significant security risks for affected organizations. It is crucial that users of luowice update to a patched version as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share