Vulnerability Details CVE-2023-31143
mage-ai is an open-source data pipeline tool for transforming and integrating data. Those who use Mage starting in version 0.8.34 and prior to 0.8.72 with user authentication enabled may be affected by a vulnerability. The terminal could be accessed by users who are not signed in or do not have editor permissions. Version 0.8.72 contains a fix for this issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 31.0%
CVSS Severity
CVSS v3 Score 5.9
Products affected by CVE-2023-31143
-
cpe:2.3:a:mage:mage-ai:0.8.34
-
cpe:2.3:a:mage:mage-ai:0.8.35
-
cpe:2.3:a:mage:mage-ai:0.8.36
-
cpe:2.3:a:mage:mage-ai:0.8.37
-
cpe:2.3:a:mage:mage-ai:0.8.38
-
cpe:2.3:a:mage:mage-ai:0.8.39
-
cpe:2.3:a:mage:mage-ai:0.8.40
-
cpe:2.3:a:mage:mage-ai:0.8.41
-
cpe:2.3:a:mage:mage-ai:0.8.42
-
cpe:2.3:a:mage:mage-ai:0.8.43
-
cpe:2.3:a:mage:mage-ai:0.8.44
-
cpe:2.3:a:mage:mage-ai:0.8.45
-
cpe:2.3:a:mage:mage-ai:0.8.46
-
cpe:2.3:a:mage:mage-ai:0.8.47
-
cpe:2.3:a:mage:mage-ai:0.8.48
-
cpe:2.3:a:mage:mage-ai:0.8.49
-
cpe:2.3:a:mage:mage-ai:0.8.50
-
cpe:2.3:a:mage:mage-ai:0.8.51
-
cpe:2.3:a:mage:mage-ai:0.8.52
-
cpe:2.3:a:mage:mage-ai:0.8.53
-
cpe:2.3:a:mage:mage-ai:0.8.54
-
cpe:2.3:a:mage:mage-ai:0.8.55
-
cpe:2.3:a:mage:mage-ai:0.8.56
-
cpe:2.3:a:mage:mage-ai:0.8.57
-
cpe:2.3:a:mage:mage-ai:0.8.58
-
cpe:2.3:a:mage:mage-ai:0.8.59
-
cpe:2.3:a:mage:mage-ai:0.8.60
-
cpe:2.3:a:mage:mage-ai:0.8.61
-
cpe:2.3:a:mage:mage-ai:0.8.62
-
cpe:2.3:a:mage:mage-ai:0.8.63
-
cpe:2.3:a:mage:mage-ai:0.8.64
-
cpe:2.3:a:mage:mage-ai:0.8.66
-
cpe:2.3:a:mage:mage-ai:0.8.67
-
cpe:2.3:a:mage:mage-ai:0.8.68
-
cpe:2.3:a:mage:mage-ai:0.8.69
-
cpe:2.3:a:mage:mage-ai:0.8.70
-
cpe:2.3:a:mage:mage-ai:0.8.71