CVE-2023-4588 is a file accessibility vulnerability affecting Delinea Secret Server versions v10.9.000002 and v11.4.000002. An authenticated administrative user can exploit this by changing the default backup directory to the webroot, creating a backup, and then downloading it. This action exposes sensitive configuration files, including database credentials in plain text. The vulnerability has a CVSS score of 4.9 (Medium), indicating high confidentiality impact with network access and high privileges required. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.9.000002CPE matchmatch criteria | cpe:2.3:a:delinea:secret_server:10.9.000002:*:*:*:*:*:*:* | ||
11.4.000002CPE matchmatch criteria | cpe:2.3:a:delinea:secret_server:11.4.000002:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.