Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4x48-qpw5-qpgr

Опубликовано: 20 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

Omnis Studio 10.22.00 has incorrect access control. It advertises a feature for making Omnis libraries "always private" - this is supposed to be an irreversible operation. However, due to implementation issues, "always private" Omnis libraries can be opened by the Omnis Studio browser by bypassing specific checks. This violates the expected behavior of an "irreversible operation".

Omnis Studio 10.22.00 has incorrect access control. It advertises a feature for making Omnis libraries "always private" - this is supposed to be an irreversible operation. However, due to implementation issues, "always private" Omnis libraries can be opened by the Omnis Studio browser by bypassing specific checks. This violates the expected behavior of an "irreversible operation".

EPSS

Процентиль: 23%
0.00075
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 5.3
nvd
больше 2 лет назад

Omnis Studio 10.22.00 has incorrect access control. It advertises a feature for making Omnis libraries "always private" - this is supposed to be an irreversible operation. However, due to implementation issues, "always private" Omnis libraries can be opened by the Omnis Studio browser by bypassing specific checks. This violates the expected behavior of an "irreversible operation".

EPSS

Процентиль: 23%
0.00075
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-276