PT-2024-30489 · Unknown · Zephyr Project Manager

Trương Hữu Phúc

·

Published

2024-08-18

·

Updated

2025-02-11

·

CVE-2024-43322

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zephyr Project Manager versions n/a through 3.3.100
Description The issue is related to an Authorization Bypass Through User-Controlled Key vulnerability in the Zephyr Project Manager. This allows for potential unauthorized access. The estimated number of potentially affected devices worldwide is not specified. There is no information provided about real-world incidents where this issue was exploited.
Recommendations For versions n/a through 3.3.100, update to version 3.3.101 to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the Zephyr Project Manager until the update is applied.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2024-43322

Affected Products

Zephyr Project Manager