Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9pgg-cp8m-qjgp

Опубликовано: 09 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.6

Описание

A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} allows a low privileged user to fetch, modify or delete the services of any user (including admin). This results in unauthorized access and unauthorized data manipulation.

A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} allows a low privileged user to fetch, modify or delete the services of any user (including admin). This results in unauthorized access and unauthorized data manipulation.

EPSS

Процентиль: 39%
0.00173
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 9.6
nvd
больше 1 года назад

A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} allows a low privileged user to fetch, modify or delete the services of any user (including admin). This results in unauthorized access and unauthorized data manipulation.

EPSS

Процентиль: 39%
0.00173
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-639