Improper Access Control in cloudexplorer-dev/cloudexplorer-lite
Description
Improper Access Control in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CVE-2023-2845 describes an improper access control vulnerability in CloudExplorer Lite prior to v1.1.0 allowing unauthorized access.
Vulnerability
An improper access control vulnerability exists in the CloudExplorer Lite repository prior to version v1.1.0 [1]. The flaw resides in the services/vm-service/backend/src/main/java/com/fit2cloud/provider/impl/huawei/api file, where a lack of proper authorization checks on certain API endpoints allows unauthorized users to access restricted functionality [2]. Affected versions include all releases before v1.1.0 [1].
Exploitation
An attacker can exploit this vulnerability by making crafted HTTP requests to vulnerable endpoints without requiring valid authentication or elevated privileges. No user interaction is needed for exploitation [2]. The attacker must have network access to the affected instance [2].
Impact
Successful exploitation allows an attacker to bypass access controls and perform actions intended for authenticated users only, leading to potential information disclosure and unauthorized data manipulation [2]. The specific impact depends on the attacker's ability to interact with internal services exposed by the vulnerability [1].
Mitigation
The vulnerability is fixed in version v1.1.0 of CloudExplorer Lite [1]. Users should upgrade to v1.1.0 or later immediately. As of the reference publication date (May 2023), no known workaround is available for unpatched versions [2].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <1.1.0
- cloudexplorer-dev/cloudexplorer-dev/cloudexplorer-litev5Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.