PT-2024-29960 · Unknown · Upkeeper Manager

Published

2024-08-16

·

Updated

2024-08-28

·

CVE-2024-42464

CVSS v4.0

7.6

High

VectorAV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions upKeeper Manager versions through 5.1.9
Description An Authorization Bypass Through User-Controlled Key issue exists in upKeeper Manager, allowing an attacker to utilize REST's trust in the system resource to obtain sensitive data.
Recommendations For versions through 5.1.9, update to a version later than 5.1.9 to resolve the issue. As a temporary workaround, consider restricting access to REST endpoints to minimize the risk of exploitation.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2024-42464

Affected Products

Upkeeper Manager