Описание
Kill Bill through 0.24.21 fails to enforce permission annotations on several AdminResource endpoints including getQueueEntries, invalidatesCache, and putOutOfRotation. Authenticated users with minimal account:read permissions can read internal queues, flush server caches, and disable the server by putting the host out of rotation.
Ссылки
EPSS
Процентиль: 13%
0.00219
Низкий
7.6 High
CVSS3
Дефекты
CWE-862
Связанные уязвимости
CVSS3: 7.6
github
17 дней назад
Kill Bill through 0.24.21 fails to enforce permission annotations on several AdminResource endpoints including getQueueEntries, invalidatesCache, and putOutOfRotation. Authenticated users with minimal account:read permissions can read internal queues, flush server caches, and disable the server by putting the host out of rotation.
EPSS
Процентиль: 13%
0.00219
Низкий
7.6 High
CVSS3
Дефекты
CWE-862