CVE-2023-32637
Summary
| CVE | CVE-2023-32637 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-25 06:15:00 UTC |
| Updated | 2023-11-07 04:14:00 UTC |
| Description | ** UNSUPPPORTED WHEN ASSIGNED ** GBrowse accepts files with any formats uploaded and places them in the area accessible through unauthenticated web requests. Therefore, anyone who can upload files through the product may execute arbitrary code on the server. |
Risk And Classification
Problem Types: CWE-434
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gbrowse Project | Gbrowse | - | All | All | All |
| Application | Gmod | Gbrowse | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GBrowse - GMOD | MISC | gmod.org | |
| JVN#35897618: GBrowse vulnerable to unrestricted upload of files with dangerous types | MISC | jvn.jp | |
| JBrowse | JBrowse | MISC | jbrowse.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.