Junglewise Threat Intelligence

CVE-2023-41266: Qlik Sense Path Traversal Vulnerability

CVE-2023-41266 · Severity: critical · CVSS 8.2 · Exploited in the wild · Published 2023-12-07

Technologies: Qlik Sense. Vendors: Qlik.

Executive brief

A path traversal vulnerability in Qlik Sense Enterprise for Windows allows unauthenticated remote attackers to generate anonymous sessions via crafted HTTP requests. These sessions can be used to bypass authorization and access unauthorized endpoints.

Affected products

  • Qlik Qlik Sense Enterprise for Windows May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, August 2022 Patch 12 and earlier

Timeline

  • 2023-08-29: disclosed: NVD Published Date
  • 2023-12-07: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-12-07: exploited: Reported as exploited in the wild in advisory metadata

Related threats