CVE-2023-50976
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Dec 18, 2023
Updated: Dec 22, 2023
CWE ID 862
Summary
CVE-2023-50976 is a vulnerability affecting Redpanda versions before 23.1.21 and 23.2.x up to 23.2.18. The issue lies in the Transactions API where authorization checks are missing. An unauthorized user may exploit this vulnerability to gain unapproved access, potentially leading to data manipulation or unintended actions within the system. This lack of proper access control increases the risk of data breaches or business disruptions, making it crucial for affected organizations to apply the necessary patches as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Redpanda
Affected Vendors
- APT10