Security Advisory
CVE-2023-1306
8.8
HIGH
Vulnerability Description
An authenticated attacker can leverage an exposed resource.db() accessor method to smuggle Python method calls via a Jinja template, which can lead to code execution. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version of InsightCloudSec.
Published Date
March 21, 2023
Official Source
NIST NVD Advisory