Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-47xg-jggc-w6c4

Опубликовано: 06 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

In Gatling Enterprise versions below 1.25.0, a low-privileged user that does not hold the role "admin" could perform a REST API call on read-only endpoints, allowing him to collect some information, due to missing authorization checks.

In Gatling Enterprise versions below 1.25.0, a low-privileged user that does not hold the role "admin" could perform a REST API call on read-only endpoints, allowing him to collect some information, due to missing authorization checks.

EPSS

Процентиль: 16%
0.00052
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 5.3
nvd
6 месяцев назад

In Gatling Enterprise versions below 1.25.0, a low-privileged user that does not hold the role "admin" could perform a REST API call on read-only endpoints, allowing him to collect some information, due to missing authorization checks.

EPSS

Процентиль: 16%
0.00052
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-862