Vulnerabilities > CVE-2023-43784 - Exposure of Resource to Wrong Sphere vulnerability in Plesk Onyx 17.8.11

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
plesk
CWE-668

Summary

Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE: the vendor's position is that there is no security threat.

Vulnerable Configurations

Part Description Count
Application
Plesk
1

Common Weakness Enumeration (CWE)