CVE-2023-28656

N

GINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_select_deploy:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:f5:nginx_api_connectivity_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_security_monitoring:*:*:*:*:*:*:*:*

History

19 May 2025, 14:45

Type Values Removed Values Added
First Time Netapp
Netapp ontap Select Deploy
Netapp cloud Backup
CPE cpe:2.3:a:netapp:ontap_select_deploy:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
References () https://security.netapp.com/advisory/ntap-20230609-0006/ - () https://security.netapp.com/advisory/ntap-20230609-0006/ - Third Party Advisory

13 Feb 2025, 17:16

Type Values Removed Values Added
Summary (en) NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. (en) NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

21 Nov 2024, 07:55

Type Values Removed Values Added
References () https://my.f5.com/manage/s/article/K000133417 - Vendor Advisory () https://my.f5.com/manage/s/article/K000133417 - Vendor Advisory
References () https://security.netapp.com/advisory/ntap-20230609-0006/ - () https://security.netapp.com/advisory/ntap-20230609-0006/ -

Information

Published : 2023-05-03 15:15

Updated : 2025-05-19 14:45


NVD link : CVE-2023-28656

Mitre link : CVE-2023-28656

CVE.ORG link : CVE-2023-28656


JSON object : View

CWE
CWE-639

Authorization Bypass Through User-Controlled Key