CVE-2023-22892: High severity zephyr for jira test management vulnerability
Published Mar 8, 2023
·Updated
There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users to read arbitrary files from Zephyr instances.
Affected Software
1 affected component
SMARTBEAR Zephyr Enterprise<=7.15
Event History
Mar 8, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-22892?
The severity of CVE-2023-22892 is high with a severity value of 7.5.
2
How can unauthenticated users exploit CVE-2023-22892?
Unauthenticated users can exploit CVE-2023-22892 to read arbitrary files from Zephyr instances.
3
What software is affected by CVE-2023-22892?
SmartBear Zephyr Enterprise versions up to and including 7.15.0 are affected by CVE-2023-22892.
4
Is authentication required to exploit CVE-2023-22892?
No, authentication is not required to exploit CVE-2023-22892.
5
Where can I find more information about CVE-2023-22892?
You can find more information about CVE-2023-22892 on the SmartBear website: https://smartbear.com/security/cve/