Record summary

CVE-2023-35843 has a selected CVSS score of 7.5 (high); EIP currently links 2 repository PoCs and 1 Nuclei template.

Description

NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access arbitrary files on the server by manipulating the path parameter of the /download route. This vulnerability could allow an attacker to access sensitive files and data on the server, including configuration files, source code, and other sensitive information.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 18, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
2
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 11, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

2

Repository PoCs

GitHubLserein/CVE-2023-35843Repository PoCby LsereinStars: 2Not analyzed4 files

170.5 KiB

GitHub

PoC details
GitHubb3nguang/CVE-2023-35843Repository PoCby b3nguangStars: 0Not analyzed2 files

1.7 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHNocoDB version <= 0.106.1 - Arbitrary File ReadCVSS 7.5

NocoDB through 0.106.1 has a path traversal vulnerability that allows an unauthenticated attacker to access arbitrary files on the server by manipulating the path parameter of the /download route. This vulnerability could allow an attacker to access sensitive files and data on the server, including configuration files, source code, and other sensitive information.

Impact

The vulnerability can lead to unauthorized access to sensitive information, potentially exposing user credentials, database contents, and other confidential data.

Remediation

Upgrade NocoDB to a version higher than 0.106.1 to mitigate the vulnerability.

WeaknessesCWE-22
Authorsdwisiswant0
Template tagscve2023cvenocodblfivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:nocodb:nocodb:*:*:*:*:*:*:*:*
Shodan: http.favicon.hash:-2017596142
FOFA: icon_hash=-2017596142

Source: ProjectDiscovery

References

4