PT-2024-35172 · Alldata · Alldata

Noah-Paige

·

Published

2024-11-08

·

Updated

2025-10-17

·

CVE-2024-52312

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions data.all (affected versions not specified)
Description The issue is related to inconsistent authorization permissions in data.all, which may allow an external actor with an authenticated account to perform restricted operations against DataSets and Environments.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-52312
GHSA-676J-G6G5-CHJ9

Affected Products

Alldata