Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p42p-v9g2-2qc5

Опубликовано: 10 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

An improper access control vulnerability [CWE-284] in FortiEDR Manager API 6.2.0 through 6.2.2, 6.0 all versions may allow in a shared environment context an authenticated admin with REST API permissions in his profile and restricted to a specific organization to access backend logs that include information related to other organizations.

An improper access control vulnerability [CWE-284] in FortiEDR Manager API 6.2.0 through 6.2.2, 6.0 all versions may allow in a shared environment context an authenticated admin with REST API permissions in his profile and restricted to a specific organization to access backend logs that include information related to other organizations.

EPSS

Процентиль: 42%
0.00196
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 4.3
nvd
больше 1 года назад

An improper access control vulnerability [CWE-284] in FortiEDR Manager API 6.2.0 through 6.2.2, 6.0 all versions may allow in a shared environment context an authenticated admin with REST API permissions in his profile and restricted to a specific organization to access backend logs that include information related to other organizations.

CVSS3: 4.3
fstec
больше 1 года назад

Уязвимость реализации прикладного программного интерфейса системы централизованного управления FortiEDR Manager, позволяющая нарушителю получить доступ к конфиденциальной информации

EPSS

Процентиль: 42%
0.00196
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284