PT-2024-33295 · Logpoint · Logpoint

Mehmet D. Ince

·

Published

2024-11-07

·

Updated

2024-11-08

·

CVE-2024-48953

CVSS v3.1

7.5

High

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Logpoint versions prior to 7.5.0
Description An issue was discovered in Logpoint where endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users to register their own authentication plugins, resulting in unauthorized access.
Recommendations For versions prior to 7.5.0, update to version 7.5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the endpoints for creating, editing, or deleting third-party authentication modules to prevent unauthorized access.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-48953

Affected Products

Logpoint