PT-2024-21296 · Opencti · Opencti

Walterone

·

Published

2024-05-23

·

Updated

2024-12-28

·

CVE-2024-26139

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions OpenCTI (affected versions not specified)
Description The issue is related to a lack of certain security controls on the profile edit functionality in OpenCTI, allowing an authenticated attacker with low privileges to gain administrative privileges on the web application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-26139
GHSA-QX4J-F4F2-VJW9
PYSEC-2024-296

Affected Products

Opencti