PT-2024-25015 · Vantage6 · Vantage6
Lowbartvanb
·
Published
2024-05-22
·
Updated
2024-05-24
·
CVE-2024-32969
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
vantage6 versions prior to 4.5.0rc3
Description
The issue allows collaboration administrators to add extra organizations to their collaboration, extending their influence. They can create new users for which they know the passwords and use this access to read task results of other collaborations that the included organization is involved in. This is limited to relatively trusted users with access to manage a collaboration, which reduces the impact.
Recommendations
For versions prior to 4.5.0rc3, update to version 4.5.0rc3 or later to resolve the issue. As a temporary workaround, consider restricting the ability of collaboration administrators to add new organizations or create new users until the update can be applied.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vantage6