PT-2024-25015 · Vantage6 · Vantage6

Lowbartvanb

·

Published

2024-05-22

·

Updated

2024-05-24

·

CVE-2024-32969

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions vantage6 versions prior to 4.5.0rc3
Description The issue allows collaboration administrators to add extra organizations to their collaboration, extending their influence. They can create new users for which they know the passwords and use this access to read task results of other collaborations that the included organization is involved in. This is limited to relatively trusted users with access to manage a collaboration, which reduces the impact.
Recommendations For versions prior to 4.5.0rc3, update to version 4.5.0rc3 or later to resolve the issue. As a temporary workaround, consider restricting the ability of collaboration administrators to add new organizations or create new users until the update can be applied.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-32969
GHSA-99R4-CJP4-3HMX

Affected Products

Vantage6