Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-76h3-5354-76w2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/user/{user-guid}/ user edition endpoint could permit any logged-in user to increase their own permissions via a user_permissions array in a PATCH request. A guest user could modify other users' profiles and much more.

In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/user/{user-guid}/ user edition endpoint could permit any logged-in user to increase their own permissions via a user_permissions array in a PATCH request. A guest user could modify other users' profiles and much more.

EPSS

Процентиль: 75%
0.00901
Низкий

8.8 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 7.6
nvd
больше 4 лет назад

In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/user/{user-guid}/ user edition endpoint could permit any logged-in user to increase their own permissions via a user_permissions array in a PATCH request. A guest user could modify other users' profiles and much more.

EPSS

Процентиль: 75%
0.00901
Низкий

8.8 High

CVSS3

Дефекты

CWE-863