A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part of the disclosed path.
{
"cna_assigner": "redhat",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/34xxx/CVE-2023-34968.json",
"cwe_ids": [
"CWE-201"
]
}{
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "4.16.11"
},
{
"introduced": "4.17.0"
},
{
"fixed": "4.17.10"
},
{
"introduced": "4.18.0"
},
{
"fixed": "4.18.5"
}
],
"cpe": "cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*"
}