Описание
An authorization bypass vulnerability in pinboard updates in ThoughtSpot 4.4.1 through 5.1.1 (before 5.1.2) allows a low-privilege user with write access to at least one pinboard to corrupt pinboards of another user in the application by spoofing GUIDs in pinboard update requests, effectively deleting them.
Ссылки
- Release NotesVendor Advisory
- Third Party Advisory
- Third Party Advisory
- Release NotesVendor Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 4.4.1 (включая) до 5.1.1 (включая)
cpe:2.3:a:thoughtspot:thoughtspot:*:*:*:*:*:*:*:*
EPSS
Процентиль: 56%
0.00335
Низкий
8.1 High
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-639
Связанные уязвимости
CVSS3: 8.1
github
больше 3 лет назад
An authorization bypass vulnerability in pinboard updates in ThoughtSpot 4.4.1 through 5.1.1 (before 5.1.2) allows a low-privilege user with write access to at least one pinboard to corrupt pinboards of another user in the application by spoofing GUIDs in pinboard update requests, effectively deleting them.
EPSS
Процентиль: 56%
0.00335
Низкий
8.1 High
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-639