« Volver al listado

CVE-2023-6239

Estado: ModificadaAlta (8.8)—

Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specific configuration of metadata-driven permissions in M-Files Server versions 23.9, 23.10, and 23.11 before 23.11.13168.7, potentially enabling unauthorized access to the object.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-6239",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@m-files.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@m-files.com",
      "affectedData": [
        {
          "vendor": "M-Files",
          "product": "M-Files Server",
          "versions": [
            {
              "status": "affected",
              "version": "23.9"
            },
            {
              "status": "affected",
              "version": "23.10"
            },
            {
              "status": "affected",
              "version": "23.11",
              "lessThan": "23.11.13168.7",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-11-28T14:15:07.697",
  "references": [
    {
      "url": "https://empower.m-files.com/security-advisories/CVE-2023-6239",
      "source": "security@m-files.com"
    },
    {
      "url": "https://product.m-files.com/security-advisories/cve-2023-6239/",
      "source": "security@m-files.com"
    },
    {
      "url": "https://www.m-files.com/about/trust-center/security-advisories/cve-2023-6239/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@m-files.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-281"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-281"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specific configuration of metadata-driven permissions in M-Files Server versions 23.9, 23.10, and 23.11 before 23.11.13168.7, potentially enabling unauthorized access to the object."
    },
    {
      "lang": "es",
      "value": "Los permisos efectivos calculados incorrectamente en las versiones 23.9 y 23.10 y 23.11 anteriores a 23.11.13168.7 de M-Files Server podrían producir un resultado defectuoso si un objeto usaba una configuración específica de permisos basados en metadatos."
    }
  ],
  "lastModified": "2026-06-17T06:50:22.197",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:m-files:m-files_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B408AD46-F3C1-4147-BFF2-49AC79E16427",
              "versionEndExcluding": "23.11.13168.7",
              "versionStartIncluding": "23.11"
            },
            {
              "criteria": "cpe:2.3:a:m-files:m-files_server:23.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A0E287ED-BA4E-4D59-8C0A-BAB5BD37AF82"
            },
            {
              "criteria": "cpe:2.3:a:m-files:m-files_server:23.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E279BB5-D202-4D95-BDE6-586BE204B101"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@m-files.com"
}