An attacker is able to steal secrets and potentially gain remote code execution via CSRF using the open source Prefect web server's API.
References
| Link | Resource |
|---|---|
| https://huntr.com/bounties/dab47d99-551c-4355-9ab1-c99cb90235af | Exploit |
Configurations
Information
Published : 2023-11-16 17:15
Updated : 2023-11-30 13:15
NVD link : CVE-2023-6022
Mitre link : CVE-2023-6022
JSON object : View
Products Affected
prefect
- prefect
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
