Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p8hg-fcwf-r2vv

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 2.8

Описание

A vulnerability has been identified in IBM Cloud Orchestrator services/[action]/launch API. An authenticated domain admin user might modify cross domain resources via a /services/[action]/launch API call, provided it would have been possible for the domain admin user to gain access to a resource identifier of the other domain.

A vulnerability has been identified in IBM Cloud Orchestrator services/[action]/launch API. An authenticated domain admin user might modify cross domain resources via a /services/[action]/launch API call, provided it would have been possible for the domain admin user to gain access to a resource identifier of the other domain.

EPSS

Процентиль: 26%
0.00092
Низкий

2.8 Low

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 2.8
nvd
около 9 лет назад

A vulnerability has been identified in IBM Cloud Orchestrator services/[action]/launch API. An authenticated domain admin user might modify cross domain resources via a /services/[action]/launch API call, provided it would have been possible for the domain admin user to gain access to a resource identifier of the other domain.

EPSS

Процентиль: 26%
0.00092
Низкий

2.8 Low

CVSS3

Дефекты

CWE-284