CVE-2023-32550 CRITICAL

CVE-2023-32550: Landscape's Apache server-status is accessible by default

Vendor Canonical Ltd.
Product Landscape
Weakness CWE-497
Published June 6, 2023
Last update January 7, 2025

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

What the vulnerability does

Description

Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain information to attack and leak further information from the Landscape API.

Key dates

Disclosure timeline

June 6, 2023 CVE published
January 7, 2025 Record updated