mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 02:31:38 +00:00
18 lines
927 B
Markdown
18 lines
927 B
Markdown
### [CVE-2023-50424](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-50424)
|
||

|
||

|
||

|
||
|
||
### Description
|
||
|
||
SAP BTP Security Services Integration Library ([Golang] github.com/sap/cloud-security-client-go) - versions < 0.17.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.
|
||
|
||
### POC
|
||
|
||
#### Reference
|
||
- https://blogs.sap.com/2023/12/12/unveiling-critical-security-updates-sap-btp-security-note-3411067/
|
||
|
||
#### Github
|
||
- https://github.com/fkie-cad/nvd-json-data-feeds
|
||
|