File accessibility vulnerability in Delinea Secret Server
Vulnerability Description
File accessibility vulnerability in Delinea Secret Server, in its v10.9.000002 and v11.4.000002 versions. Exploitation of this vulnerability could allow an authenticated user with administrative privileges to create a backup file in the application's webroot directory, changing the default backup directory to the wwwroot folder, and download it with some configuration files such as encryption.config/ and database.config stored in the wwwroot directory, exposing the database credentials in plain text.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-4588
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Héctor de Armas Padrón (@3v4SI0N)
References
More from Delinea
View All →Affected Vendor
Delinea
View all reports →