| id: GO-2023-1527 |
| modules: |
| - module: www.velocidex.com/golang/velociraptor |
| versions: |
| - fixed: 0.6.7-5 |
| vulnerable_at: 0.6.7-4 |
| summary: Velociraptor vulnerable to Missing Authorization in www.velocidex.com/golang/velociraptor |
| cves: |
| - CVE-2023-0242 |
| ghsas: |
| - GHSA-g5vm-525q-r66c |
| references: |
| - advisory: https://github.com/advisories/GHSA-g5vm-525q-r66c |
| - advisory: https://nvd.nist.gov/vuln/detail/CVE-2023-0242 |
| - web: https://docs.velociraptor.app/announcements/2023-cves/#:~:text=to%20upgrade%20clients.-,CVE%2D2023%2D0242,-Insufficient%20Permission%20Check |
| source: |
| id: GHSA-g5vm-525q-r66c |
| created: 2024-08-20T11:30:44.889318-04:00 |
| review_status: UNREVIEWED |
| unexcluded: EFFECTIVELY_PRIVATE |