S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2023-29922 Scanner

Detects 'Improper Access Control' vulnerability in PowerJob affects v. 4.3.1.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-29922
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create user/save interface.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

PowerJob is a software that is used for processing big data, building data pipelines and performing complex data tasks. It is a job scheduling and workflow orchestration framework that can be used on various platforms including Hadoop, Spark, and Flink. This software allows users to run, schedule and monitor data processes, offering a unified interface for all data processing needs.

CVE-2023-29922 is a vulnerability that was detected in PowerJob V4.3.1. This vulnerability is categorized as an Incorrect Access Control issue, which means that unauthorized access to the system can malfunction it. The vulnerability appears in the create user/save interface, which means that attackers can manipulate this feature to bypass access control mechanisms and gain unauthorized access to the system.

When exploited, this vulnerability can lead to serious consequences such as data loss, data corruption, and unauthorized access to sensitive data. The vulnerability can also lead to the complete takeover of the system by attackers. Attackers can use this vulnerability to tamper with data, cause downtime or launch other types of attacks on the system that can cause harm to the business.

In conclusion, PowerJob is a great tool for data processing, but like any software, it is susceptible to vulnerabilities. Users must take the necessary precautions to protect their data and systems from potential attacks. With the pro features of the s4e.io platform, users can stay up to date with the latest vulnerabilities and threats, and learn how to protect their digital assets more easily and quickly.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are several precautions users can take including:

  • Updating PowerJob to the latest version
  • Applying all security patches and updates
  • Configuring the access control settings appropriately
  • Restricting access to the system only to authorized personnel
  • Monitoring the system closely for unusual activity

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-29922 scanner - Improper Access Control vulnerability in PowerJob | S4E