CVE-2024-4843

ePO doesn't allow a regular privileged user to delete tasks or assignments. Insecure direct object references that allow a least privileged user to manipulate the client task and client task assignments, hence escalating his/her privilege.
Configurations

No configuration.

History

21 Nov 2024, 09:43

Type Values Removed Values Added
References () https://thrive.trellix.com/s/article/000013505 - () https://thrive.trellix.com/s/article/000013505 -
Summary
  • (es) ePO no permite que un usuario privilegiado normal elimine tareas o asignaciones. Referencias a objetos directos inseguras que permiten que un usuario con menos privilegios manipule la tarea del cliente y las asignaciones de tareas del cliente, aumentando así sus privilegios.

16 May 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-16 06:15

Updated : 2024-11-21 09:43


NVD link : CVE-2024-4843

Mitre link : CVE-2024-4843

CVE.ORG link : CVE-2024-4843


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key