PT-2023-23084 · Foundry · Workspace-Server
Published
2023-06-29
·
Updated
2023-07-07
·
CVE-2023-30955
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Foundry workspace-server versions prior to 7.7.0
Description
A security defect was identified in Foundry workspace-server that enabled a user to bypass an authorization check and view settings related to 'Developer Mode'. This allowed users with insufficient privilege to view and interact with Developer Mode settings in a limited capacity.
Recommendations
For versions prior to 7.7.0, update to workspace-server 7.7.0 to resolve the issue. As a temporary workaround, consider restricting access to Developer Mode settings until the update is applied.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Workspace-Server