EXPOSURES › CVE-2023-41266
CVE-2023-41266
CRITICAL ⌖ ON CISA KEV · EXPLOITEDQlik Sense path traversal flaw lets unauthenticated attackers create anonymous sessions to hit unauthorized endpoints.
A remote, unauthenticated attacker can exploit a path traversal vulnerability in Qlik Sense to create anonymous sessions and access unauthorized endpoints. This is a critical, actively exploited vulnerability linked to ransomware, meaning DIB organizations using Qlik Sense face immediate exposure to data theft and ransomware attacks. Organizations must patch this vulnerability immediately and assess their Qlik Sense deployments for exposure.
Shame score — A critical, actively exploited vulnerability linked to ransomware that allows unauthenticated attackers to bypass access controls and access unauthorized endpoints.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Qlik Sense contains a path traversal vulnerability that allows a remote, unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the attacker to send further requests to unauthorized endpoints.
| PRODUCT | STATUS |
|---|---|
| Qlik Cloud Government Qlik Technologies Inc. |
Authorized |