Information Exposure Affecting samba package, versions [,4.16.11)[4.17.0,4.17.10)[4.18.0,4.18.5)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.33% (71st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-SAMBA-5798517
  • published21 Jul 2023
  • disclosed19 Jul 2023
  • creditRalph Boehme, Stefan Metzmacher

Introduced: 19 Jul 2023

CVE-2023-34968  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade samba to version 4.16.11, 4.17.10, 4.18.5 or higher.

Overview

Affected versions of this package are vulnerable to Information Exposure. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part of the disclosed path.

CVSS Scores

version 3.1