CVE-2024-49373

No Fuss Computing Centurion ERP is open source enterprise resource planning (ERP) software. Prior to version 1.2.1, an authenticated user can view projects within organizations they are not apart of. Version 1.2.1 fixes the problem.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nofusscomputing:centurion_erp:*:*:*:*:*:*:*:*

History

30 Oct 2024, 21:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.1
v2 : unknown
v3 : 4.3
References () https://github.com/nofusscomputing/centurion_erp/commit/c3a4685200faa060167d4fde86e806dc91eddcae - () https://github.com/nofusscomputing/centurion_erp/commit/c3a4685200faa060167d4fde86e806dc91eddcae - Patch
References () https://github.com/nofusscomputing/centurion_erp/pull/358 - () https://github.com/nofusscomputing/centurion_erp/pull/358 - Patch
References () https://github.com/nofusscomputing/centurion_erp/security/advisories/GHSA-5qmx-pr2f-qhj5 - () https://github.com/nofusscomputing/centurion_erp/security/advisories/GHSA-5qmx-pr2f-qhj5 - Vendor Advisory
CWE NVD-CWE-noinfo
First Time Nofusscomputing
Nofusscomputing centurion Erp
CPE cpe:2.3:a:nofusscomputing:centurion_erp:*:*:*:*:*:*:*:*

23 Oct 2024, 15:12

Type Values Removed Values Added
Summary
  • (es) No Fuss Computing Centurion ERP es un software de planificación de recursos empresariales (ERP) de código abierto. Antes de la versión 1.2.1, un usuario autenticado podía ver proyectos dentro de organizaciones de las que no formaba parte. La versión 1.2.1 soluciona el problema.

22 Oct 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-22 16:15

Updated : 2024-10-30 21:16


NVD link : CVE-2024-49373

Mitre link : CVE-2024-49373

CVE.ORG link : CVE-2024-49373


JSON object : View

Products Affected

nofusscomputing

  • centurion_erp
CWE
NVD-CWE-noinfo CWE-653

Insufficient Compartmentalization