« Volver al listado

CVE-2023-6562

Estado: ModificadaAlta (7.5)—

JPX Fragment List (flst) box vulnerability in Kakadu 7.9 allows an attacker to exfiltrate local and remote files reachable by a server if the server allows the attacker to upload a specially-crafted the image that is displayed back to the attacker.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-6562",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve-coordination@google.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve-coordination@google.com",
      "affectedData": [
        {
          "vendor": "Kakadu Software Pty Ltd",
          "product": "Kakadu SDK",
          "versions": [
            {
              "status": "affected",
              "version": "4.4",
              "lessThan": "8.4",
              "versionType": "python"
            }
          ],
          "packageName": "JPEG 2000, JPX",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-12-20T13:15:07.260",
  "references": [
    {
      "url": "https://github.com/google/security-research/security/advisories/GHSA-g6qc-fhcq-vhf9",
      "tags": [
        "Exploit"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://github.com/google/security-research/security/advisories/GHSA-g6qc-fhcq-vhf9",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve-coordination@google.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-434"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "JPX Fragment List (flst) box vulnerability in Kakadu 7.9 allows an attacker to exfiltrate local and remote files reachable by a server if the server allows the attacker to upload a specially-crafted the image that is displayed back to the attacker.\n"
    },
    {
      "lang": "es",
      "value": "La vulnerabilidad de la JPX Fragment List (flst) box en Kakadu 7.9 permite a un atacante exfiltrar archivos locales y remotos a los que puede acceder un servidor si el servidor le permite cargar una imagen especialmente manipulada que se muestra al atacante."
    }
  ],
  "lastModified": "2026-06-17T06:50:59.730",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:kakadusoftware:kakadu_sdk:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "078B32B4-84BD-4308-8B19-34AC6226E5B5",
              "versionEndIncluding": "8.4",
              "versionStartIncluding": "4.4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve-coordination@google.com"
}