Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x255-qvfv-83jw

Опубликовано: 23 мая 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.8

Описание

A Broken Access Control vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, and 5.4.0 before 5.4.10 allows remote, authenticated, and unprivileged users to retrieve alerts, cases, logs, observables, or tasks, regardless of the user's permissions, through a specific API endpoint.

A Broken Access Control vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, and 5.4.0 before 5.4.10 allows remote, authenticated, and unprivileged users to retrieve alerts, cases, logs, observables, or tasks, regardless of the user's permissions, through a specific API endpoint.

EPSS

Процентиль: 21%
0.0007
Низкий

6.8 Medium

CVSS4

Дефекты

CWE-266

Связанные уязвимости

nvd
9 месяцев назад

A Broken Access Control vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, and 5.4.0 before 5.4.10 allows remote, authenticated, and unprivileged users to retrieve alerts, cases, logs, observables, or tasks, regardless of the user's permissions, through a specific API endpoint.

EPSS

Процентиль: 21%
0.0007
Низкий

6.8 Medium

CVSS4

Дефекты

CWE-266