CVE-2023-49801 - CVE House
Back to Database
Status published Medium CVE-2023-49801

Lif Auth Server vulnerable to uncontrolled data in path expression

Vulnerability Description

Lif Auth Server is a server for validating logins, managing information, and account recovery for Lif Accounts. The issue relates to the `get_pfp` and `get_banner` routes on Auth Server. The issue is that there is no check to ensure that the file that Auth Server is receiving through these URLs is correct. This could allow an attacker access to files they shouldn't have access to. This issue has been patched in version 1.4.0.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-49801

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Lif-Platforms

View all reports →

Affected Software

Lif-Auth-Server
Vulnerable Versions:
>= 1.3.2, < 1.4.0

Timeline

Official Publish: January 12th, 2024
Last Modified: November 14th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Weaknesses (CWE)