Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-85213

Опубликовано: 03 сент. 2026
Источник: nvd
CVSS3: 7.6
EPSS Низкий

Описание

Kill Bill through 0.24.21 fails to enforce permission annotations on several AdminResource endpoints including getQueueEntries, invalidatesCache, and putOutOfRotation. Authenticated users with minimal account:read permissions can read internal queues, flush server caches, and disable the server by putting the host out of rotation.

EPSS

Процентиль: 13%
0.00219
Низкий

7.6 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.6
github
17 дней назад

Kill Bill through 0.24.21 fails to enforce permission annotations on several AdminResource endpoints including getQueueEntries, invalidatesCache, and putOutOfRotation. Authenticated users with minimal account:read permissions can read internal queues, flush server caches, and disable the server by putting the host out of rotation.

EPSS

Процентиль: 13%
0.00219
Низкий

7.6 High

CVSS3

Дефекты

CWE-862