Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h9cv-6mcv-ffr4

Опубликовано: 19 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 6.1

Описание

Insufficient authentication in user account management in Yugabyte Platform allows local network attackers with a compromised user session to change critical security information without re-authentication. An attacker with user session and access to application can modify settings such as password and email without being prompted for the current password, enabling account takeover.

Insufficient authentication in user account management in Yugabyte Platform allows local network attackers with a compromised user session to change critical security information without re-authentication. An attacker with user session and access to application can modify settings such as password and email without being prompted for the current password, enabling account takeover.

EPSS

Процентиль: 19%
0.00061
Низкий

6.1 Medium

CVSS4

Дефекты

CWE-306

Связанные уязвимости

nvd
больше 1 года назад

Insufficient authentication in user account management in Yugabyte Platform allows local network attackers with a compromised user session to change critical security information without re-authentication. An attacker with user session and access to application can modify settings such as password and email without being prompted for the current password, enabling account takeover.

debian
больше 1 года назад

Insufficient authentication in user account management in Yugabyte Pla ...

EPSS

Процентиль: 19%
0.00061
Низкий

6.1 Medium

CVSS4

Дефекты

CWE-306