PT-2024-3648 · Apache+1 · Apache Lucene+1
Luis Manuel Alvarez Tapia
·
Published
2024-05-14
·
Updated
2024-07-07
·
CVE-2024-33647
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Polarion ALM versions prior to 2404.0
Description
A vulnerability has been identified in the Apache Lucene based query engine of Polarion ALM, which lacks proper access controls. This could allow an authenticated user to query items beyond the user's allowed projects, potentially granting unauthorized access to restricted functions.
Recommendations
For versions prior to 2404.0, upgrade to the latest version to mitigate the risk associated with the improper access via the Query Engine. As a temporary workaround, consider restricting access to the query engine until a patch is available.
Fix
Improper Access Control
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Lucene
Polarion Alm