PT-2024-3648 · Apache+1 · Apache Lucene+1

Luis Manuel Alvarez Tapia

·

Published

2024-05-14

·

Updated

2024-07-07

·

CVE-2024-33647

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Polarion ALM versions prior to 2404.0
Description A vulnerability has been identified in the Apache Lucene based query engine of Polarion ALM, which lacks proper access controls. This could allow an authenticated user to query items beyond the user's allowed projects, potentially granting unauthorized access to restricted functions.
Recommendations For versions prior to 2404.0, upgrade to the latest version to mitigate the risk associated with the improper access via the Query Engine. As a temporary workaround, consider restricting access to the query engine until a patch is available.

Fix

Improper Access Control

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-03973
CVE-2024-33647

Affected Products

Apache Lucene
Polarion Alm