Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-44836

Опубликовано: 18 янв. 2022
Источник: nvd
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

An issue was discovered in Delta RM 1.2. The /risque/risque/workflow/reset endpoint is lacking access controls, and it is possible for an unprivileged user to reopen a risk with a POST request, using the risqueID parameter to identify the risk to be re-opened.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:deltarm:delta_rm:1.2:*:*:*:*:*:*:*

EPSS

Процентиль: 37%
0.00158
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 4.3
github
около 4 лет назад

An issue was discovered in Delta RM 1.2. The /risque/risque/workflow/reset endpoint is lacking access controls, and it is possible for an unprivileged user to reopen a risk with a POST request, using the risqueID parameter to identify the risk to be re-opened.

EPSS

Процентиль: 37%
0.00158
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-639