Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-78cj-mhpr-2qfm

Опубликовано: 03 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

If an attacked was given access to an instance with the admin or manager role there is no backend authentication that would prevent the attacked from creating a new user with an admin role and then be able to use this new account to have elevated privileges on the instance

If an attacked was given access to an instance with the admin or manager role there is no backend authentication that would prevent the attacked from creating a new user with an admin role and then be able to use this new account to have elevated privileges on the instance

EPSS

Процентиль: 61%
0.0041
Низкий

7.2 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 7.2
nvd
почти 2 года назад

If an attacked was given access to an instance with the admin or manager role there is no backend authentication that would prevent the attacked from creating a new user with an `admin` role and then be able to use this new account to have elevated privileges on the instance

EPSS

Процентиль: 61%
0.0041
Низкий

7.2 High

CVSS3

Дефекты

CWE-284