CVE-2023-35154

    Dashboard / Vulnerabilities / CVE-2023-35154

    CVE-2023-35154

    Published: 23 Jun 2023Last Modified: 12 Aug 2026

    Summary: Knowage-Server vulnerable to account validation bypass

    Details: Knowage is an open source analytics and business intelligence suite. Starting in version 6.0.0 and prior to version 8.1.8, an attacker can register and activate their account without having to click on the link included in the email, allowing them access to the application as a normal user. This issue has been patched in version 8.1.8.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- eb0a58ddc4badcbf4502ca523cf415743c023aa0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-35154 | CVE-DB