MEDIUM
Dell Streaming Data Platform prior to 1.4 contains Open Redirect vulnerability
Published Apr 5, 2023
6.1
MEDIUMCVSS 3.1
EPSS 0.43%
Description
Dell Streaming Data Platform prior to 1.4 contains Open Redirect vulnerability. A remote unauthenticated attacker can phish the legitimate user to redirect to malicious website leading to information disclosure and launch of phishing attacks.
Affected products
-
- Version 1.1.x, 1.2.x, 1.3.xStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Dell | Streaming Data Platform | unaffected |
|
- < 1.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-31794 Advisory
- https://www.dell.com/support/kbdoc/en-us/000204266/dsa-2022-258-dell-streaming-data-platform-security-update-for-multiple-third-party-component-vulnerabilities vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-31794 | Advisory | |
| https://www.dell.com/support/kbdoc/en-us/000204266/dsa-2022-258-dell-streaming-data-platform-security-update-for-multiple-third-party-component-vulnerabilities | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner dell
Published Apr 5, 2023
Updated Feb 10, 2025
Reserved Mar 10, 2023
Link CVE-2023-28069
CISA Vulnrichment
Updated Feb 10, 2025
ENISA EUVD
EUVD-2023-31794 Assigner dell
Published Apr 5, 2023
Updated Feb 10, 2025
Exploited since n/a
Link EUVD-2023-31794