PT-2024-22255 · Bonitasoft · Bonitasoft Runtime Community Edition

Published

2024-05-15

·

Updated

2024-09-05

·

CVE-2024-28087

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Bonitasoft runtime Community edition (affected versions not specified)
Description The issue is related to the lack of dynamic permissions in the Community edition of Bonitasoft runtime, which causes an Insecure Direct Object Reference (IDOR) issue. It is mentioned that dynamic permissions were previously only available in the Subscription edition but have now been added to the Community edition, albeit without customization options.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

IDOR

Weakness Enumeration

Related Identifiers

CVE-2024-28087
GHSA-76V2-48W6-CRXR

Affected Products

Bonitasoft Runtime Community Edition