PT-2024-40044 · Neos · Neos
Published
2024-05-17
·
Updated
2024-05-17
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Neos (affected versions not specified)
Description
The issue allows unauthorized access to internal workspaces in Neos without authentication. This means that internal workspaces, which are non-public and do not have an owner, can be viewed by anyone who knows the workspace name, including a unique hash. The impact is somewhat mitigated because there is no default internal workspace, so only user-created workspaces are affected. An attacker would need to obtain the workspace name, including the hash, to exploit the issue. This can be done through brute force or educated guesses, although it is not a trivial task.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Neos