PT-2024-21964 · Alldata · Alldata

·

CVE-2024-27605

·

Published

2024-04-02

·

Updated

2024-04-03

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Alldata version 0.4.6
Description The issue allows users, such as test, to query information about the users in the system due to insecure permissions.
Recommendations For Alldata version 0.4.6, restrict access to sensitive user information to prevent unauthorized queries. As a temporary workaround, consider limiting the privileges of the test user until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-27605

Affected Products

Alldata