cvelist/2023/28xxx/CVE-2023-28124.json

62 lines
2.0 KiB
JSON
Raw Normal View History

2023-03-10 20:00:35 +00:00
{
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
"CVE_data_meta": {
"ID": "CVE-2023-28124",
2023-04-19 20:00:37 +00:00
"ASSIGNER": "support@hackerone.com",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "n/a",
"product": {
"product_data": [
{
"product_name": "UI Desktop for Windows",
"version": {
"version_data": [
{
"version_value": "Fixed on Version 0.62.3 or later."
}
]
}
}
]
}
}
]
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Inadequate Encryption Strength (CWE-326)"
}
]
}
]
},
"references": {
"reference_data": [
{
"refsource": "MISC",
"name": "https://community.ui.com/releases/Security-Advisory-Bulletin-029-029/a47c68f2-1f3a-47c3-b577-eb70599644e4",
"url": "https://community.ui.com/releases/Security-Advisory-Bulletin-029-029/a47c68f2-1f3a-47c3-b577-eb70599644e4"
}
]
2023-03-10 20:00:35 +00:00
},
"description": {
"description_data": [
{
"lang": "eng",
2023-04-19 20:00:37 +00:00
"value": "Improper usage of symmetric encryption in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow users with access to UI Desktop configuration files to decrypt their content.This vulnerability is fixed in Version 0.62.3 and later."
2023-03-10 20:00:35 +00:00
}
]
}
}