PT-2020-17048 · Openasset · Openasset Digital Asset Management
Jack Misiura
·
Published
2020-12-14
·
Updated
2020-12-15
·
CVE-2020-28861
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenAsset Digital Asset Management (DAM) versions 12.0.19 and earlier
Description
The issue is related to a lack of access controls on the "Stream/ProjectsCSV" endpoint, allowing unauthenticated attackers to access potentially sensitive project information stored by the application.
Recommendations
For versions 12.0.19 and earlier, consider disabling access to the "Stream/ProjectsCSV" endpoint until a patch is available to implement proper access controls. Restrict access to this endpoint to minimize the risk of exploitation.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openasset Digital Asset Management