AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-1305

HIGH · CVSS 8.1 EPSS 0.78%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-03-21 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2023-1305
Severity
HIGH
CVSS
8.1
EPSS
0.78%

Original NVD Description

An authenticated attacker can leverage an exposed “box” object to read and write arbitrary files from disk, provided those files can be parsed as yaml or JSON. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version of InsightCloudSec.