Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c4pf-hc84-698h

Опубликовано: 07 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users to register their own authentication plugins in Logpoint, resulting in unauthorized access.

An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users to register their own authentication plugins in Logpoint, resulting in unauthorized access.

EPSS

Процентиль: 40%
0.00183
Низкий

7.5 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users to register their own authentication plugins in Logpoint, resulting in unauthorized access.

EPSS

Процентиль: 40%
0.00183
Низкий

7.5 High

CVSS3

Дефекты

CWE-306