PT-2024-13678 · Unknown · Kiuwan Sast
Constantin Schwarz
+1
·
Published
2024-06-20
·
Updated
2024-07-03
·
CVE-2023-49112
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Kiuwan SAST version <master.1808.p685.q13371>
Description
The issue concerns an API endpoint "/saas/rest/v1/info/application" that allows access to information about any application, using the
application parameter. This endpoint lacks proper access control, enabling other authenticated users to read application information without the necessary rights.Recommendations
For Kiuwan SAST version <master.1808.p685.q13371>, consider restricting access to the "/saas/rest/v1/info/application" API endpoint until a proper fix is available. As a temporary workaround, limit the use of the
application parameter in this endpoint to minimize the risk of unauthorized access.Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kiuwan Sast