Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9r66-8r5r-2mqr

Опубликовано: 19 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Turms IM Server v0.10.0-SNAPSHOT and earlier contains a broken access control vulnerability in the user online status query functionality. The handleQueryUserOnlineStatusesRequest() method in UserServiceController.java allows any authenticated user to query the online status, device information, and login timestamps of arbitrary users without proper authorization checks.

Turms IM Server v0.10.0-SNAPSHOT and earlier contains a broken access control vulnerability in the user online status query functionality. The handleQueryUserOnlineStatusesRequest() method in UserServiceController.java allows any authenticated user to query the online status, device information, and login timestamps of arbitrary users without proper authorization checks.

EPSS

Процентиль: 8%
0.00031
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 6.5
nvd
около 2 месяцев назад

Turms IM Server v0.10.0-SNAPSHOT and earlier contains a broken access control vulnerability in the user online status query functionality. The handleQueryUserOnlineStatusesRequest() method in UserServiceController.java allows any authenticated user to query the online status, device information, and login timestamps of arbitrary users without proper authorization checks.

EPSS

Процентиль: 8%
0.00031
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284