PT-2023-23347 · Apache · Apache Streampipes

Xun Bai

·

Publicado

2023-06-23

·

Atualizado

2024-10-09

·

CVE-2023-31469

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache StreamPipes versions 0.69.0 through 0.91.0
Description A REST interface in Apache StreamPipes was not properly restricted to admin-only access. This allowed a non-admin user with valid login credentials to elevate privileges beyond the initially assigned roles.
Recommendations For Apache StreamPipes versions 0.69.0 through 0.91.0, upgrade to StreamPipes 0.92.0 to resolve the issue. As a temporary workaround, consider restricting access to the REST interface to minimize the risk of exploitation.

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-31469
GHSA-PM73-X2H5-CMJ3

Produtos afetados

Apache Streampipes