ArcGIS Trust Center

Portal for ArcGIS Enterprise Sites 2023 Security Patch is now available

Portal for ArcGIS Enterprise Sites Security Patch is now available. This patch contains fixes for one high security issue and multiple medium priority security issues. Esri highly recommends customers using Portal for ArcGIS 11.1 through 10.8.1 to install this patch. Users at version 10.7.1 should upgrade to 10.9.1 or 11.1 and install this patch. ArcGIS 10.7.1 is in mature support status and no longer receives patches. Users working with ArcGIS Enterprise 10.7.1 and below are encouraged to upgrade to versions 11.1 (preferred), 10.9.1 or 10.8.1 and install available security patches.

This patch was released on June 28, 2023 and is available here.

 

We provide Common Vulnerability Scoring System v.3.1 (CVSS) scores to allow our customers to better assess risk of these vulnerabilities to their operations.  Both base and modified temporal scores are provided to reflect the availability of an official patch.

Vulnerabilities fixed by this patch

There is a Cross-site Scripting vulnerability in Esri Portal Sites in versions 10.8.1 – 11.1 that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser.  The privileges required to execute this attack are high.

CVE Details: CVE-2023-25835

ESRI Bug ID:  [BUG-000153659 – A stored Cross Site Scripting (XSS) vulnerability in ArcGIS Enterprise Sites.]

There is a Cross-site Scripting vulnerability in Esri Portal Sites in versions 10.8.1 – 10.9 that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser.  The privileges required to execute this attack are low.

CVE Details: CVE-2023-25836

ESRI Bug ID: [BUG-000135364 -There is a cross-site scripting (XSS) vulnerability in ArcGIS Enterprise Sites.]

There is a Cross-site Scripting vulnerability in Esri Portal Sites in versions 10.8.1 – 10.9 that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser.  The privileges required to execute this attack are high.

CVE Details: CVE-2023-25837

ESRI Bug ID: [BUG-000133088 – XSS in ArcGIS Enterprise sites.]

Next Article

Join Hacktoberfest 2023: Celebrate Open Source with Us!

Read this article