PT-2023-20659 · Cerebrate · Cerebrate
Published
2023-02-23
·
Updated
2023-03-03
·
CVE-2023-26468
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Cerebrate version 1.12
Description
The issue arises from the improper consideration of
organisation id during the creation of API keys. This could potentially lead to unauthorized access or misuse of API keys.Recommendations
For Cerebrate version 1.12, consider restricting access to API key creation until a proper fix is implemented to correctly handle
organisation id. As a temporary workaround, manually verify the organisation id for each API key created to ensure it aligns with the intended organization.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cerebrate