PT-2024-21964 · Alldata · Alldata

Raybye

·

Published

2024-04-02

·

Updated

2024-04-03

·

CVE-2024-27605

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Alldata version 0.4.6
Description The issue allows users, such as test, to query information about the users in the system due to insecure permissions.
Recommendations For Alldata version 0.4.6, restrict access to sensitive user information to prevent unauthorized queries. As a temporary workaround, consider limiting the privileges of the test user until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-27605

Affected Products

Alldata