CVE-2023-45823Disclosure(artifacthub / hub)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for CNCF projects. During a security audit of Artifact Hub's code base a security researcher identified a bug in which by using symbolic links in certain kinds of repositories loaded into Artifact Hub, it was possible to read internal files. Artifact Hub indexes content from a variety of sources, including git repositories. When processing git based repositories, Artifact Hub clones the repository and, depending on the artifact kind, reads some files from it. During this process, in some cases, no validation was done to check if the file was a symbolic link. This made possible to read arbitrary files in the system, potentially leaking sensitive information. This issue has been resolved in version `1.16.0`. Users are advised to upgrade. There are no known workarounds for this vulnerability.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • hub

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
hub

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-06: 1Technical Details · 2026-05-06: 105-06
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • DailyCVE@dailycve
    Disclosure

    🔴 Jdbi (jdbi3-freemarker), Improper Template Engine Neutralization (CWE-1336), #CVE-2023-45823 (Critical) https://dailycve.com/jdbi-jdbi3-freemarker-improper-template-engine-neutralization-cwe-1336-cve-2023-45823-critical/

    Post summary

    The tweet announces a new critical CVE (CVE‑2023‑45823) in Jdbi3‑freemarker, detailing it as an Improper Template Engine Neutralization (CWE‑1336); no exploitation, patch, or mitigation info is provided.

    0000056
    196 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appartifacthubhub---

Explore more