CVE-2024-0879

Authentication bypass in vector-admin allows a user to register to a vector-admin server while “domain restriction” is active, even when not owning an authorized email address.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mintplexlabs:vector_admin:*:*:*:*:*:*:*:*

History

31 Jan 2024, 19:16

Type Values Removed Values Added
CPE cpe:2.3:a:mintplexlabs:vector_admin:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
References () https://github.com/Mintplex-Labs/vector-admin/pull/128/commits/a581b8177dd6be719a5ef6d3ce4b1e939636bb41 - () https://github.com/Mintplex-Labs/vector-admin/pull/128/commits/a581b8177dd6be719a5ef6d3ce4b1e939636bb41 - Patch
References () https://research.jfrog.com/vulnerabilities/vector-admin-filter-bypass/ - () https://research.jfrog.com/vulnerabilities/vector-admin-filter-bypass/ - Patch, Third Party Advisory

25 Jan 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-25 15:15

Updated : 2024-02-05 00:22


NVD link : CVE-2024-0879

Mitre link : CVE-2024-0879

CVE.ORG link : CVE-2024-0879


JSON object : View

Products Affected

mintplexlabs

  • vector_admin
CWE
CWE-287

Improper Authentication