CVE-2023-43784
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Sep 22, 2023
Updated: Aug 2, 2024
CWE ID 668
Summary
CVE-2023-43784 refers to a vulnerability in Plesk Onyx 17.8.11, where accessKeyId and secretAccessKey fields, associated with an Amazon AWS Firehose component, are exposed. While the vendor holds that there is no imminent threat, this issue might potentially allow unauthorized access or manipulation of AWS Firehose data if left unaddressed. Users are advised to apply the available patch or follow the recommended security practices to mitigate potential risks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Plesk Onyx
Affected Vendors
- Plesk International GmbH