PT-2024-29960 · Unknown · Upkeeper Manager
Published
2024-08-16
·
Updated
2024-08-28
·
CVE-2024-42464
CVSS v4.0
7.6
High
| Vector | AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
upKeeper Manager versions through 5.1.9
Description
An Authorization Bypass Through User-Controlled Key issue exists in upKeeper Manager, allowing an attacker to utilize REST's trust in the system resource to obtain sensitive data.
Recommendations
For versions through 5.1.9, update to a version later than 5.1.9 to resolve the issue.
As a temporary workaround, consider restricting access to REST endpoints to minimize the risk of exploitation.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Upkeeper Manager