PT-2023-23347 · Apache · Apache Streampipes
Xun Bai
·
Publicado
2023-06-23
·
Atualizado
2024-10-09
·
CVE-2023-31469
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache StreamPipes versions 0.69.0 through 0.91.0
Description
A REST interface in Apache StreamPipes was not properly restricted to admin-only access. This allowed a non-admin user with valid login credentials to elevate privileges beyond the initially assigned roles.
Recommendations
For Apache StreamPipes versions 0.69.0 through 0.91.0, upgrade to StreamPipes 0.92.0 to resolve the issue. As a temporary workaround, consider restricting access to the REST interface to minimize the risk of exploitation.
Correção
Improper Privilege Management
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Streampipes