Описание
Mythic before 3.4.0.60 contains a broken hasura permission filter on the payload_build_step table with an always-satisfied _or condition that bypasses operation-scoped access controls. Authenticated operators and spectators can query payload_build_step to read step_stdout, step_stderr, step_name, and step_description across all operations on the server.
Ссылки
- Patch
- Issue Tracking
- Release Notes
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.4.0.60 (исключая)
cpe:2.3:a:its-a-feature:mythic:*:*:*:*:*:*:*:*
EPSS
Процентиль: 36%
0.00434
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-863
Связанные уязвимости
CVSS3: 6.5
github
2 месяца назад
Mythic before 3.4.0.60 contains a broken hasura permission filter on the payload_build_step table with an always-satisfied _or condition that bypasses operation-scoped access controls. Authenticated operators and spectators can query payload_build_step to read step_stdout, step_stderr, step_name, and step_description across all operations on the server.
EPSS
Процентиль: 36%
0.00434
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-863