CVE-2023-38335
Summary
| CVE | CVE-2023-38335 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-20 18:15:00 UTC |
| Updated | 2023-07-31 18:42:00 UTC |
| Description | Omnis Studio 10.22.00 has incorrect access control. It advertises a feature for making Omnis libraries "always private" - this is supposed to be an irreversible operation. However, due to implementation issues, "always private" Omnis libraries can be opened by the Omnis Studio browser by bypassing specific checks. This violates the expected behavior of an "irreversible operation". |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Omnis Studio 10.22.00 Library Setting Bypass ≈ Packet Storm | MISC | packetstormsecurity.com | |
| www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2023-005.txt | MISC | www.syss.de | |
| SecLists.Org Security Mailing List Archive | FULLDISC | seclists.org | |
| Full Disclosure: [SYSS-2023-005]: Omnis Studio - Expected Behavior Violation (CWE-440) (CVE-2023-38335) | FULLDISC | seclists.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.