Skip to content
COOEY

EXPOSURES › CVE-2023-41266

CVE-2023-41266

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-12-07 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-41266 ↗
⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwareexploited-in-wildunpatched

Qlik Sense path traversal flaw lets unauthenticated attackers create anonymous sessions to hit unauthorized endpoints.

A remote, unauthenticated attacker can exploit a path traversal vulnerability in Qlik Sense to create anonymous sessions and access unauthorized endpoints. This is a critical, actively exploited vulnerability linked to ransomware, meaning DIB organizations using Qlik Sense face immediate exposure to data theft and ransomware attacks. Organizations must patch this vulnerability immediately and assess their Qlik Sense deployments for exposure.

Shame score — A critical, actively exploited vulnerability linked to ransomware that allows unauthenticated attackers to bypass access controls and access unauthorized endpoints.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Qlik Sense contains a path traversal vulnerability that allows a remote, unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the attacker to send further requests to unauthorized endpoints.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Qlik Cloud Government
Qlik Technologies Inc.
Authorized