PT-2025-13650 · Tracing · Tracing

Published

2025-03-31

·

Updated

2025-04-01

·

CVE-2025-3014

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Tracking version 2.1.4
Description The issue is related to Insecure Direct Object References (IDOR) in access control, allowing an attacker to access sensitive information by manipulating request parameters or object references. This can be exploited by altering the request parameters or object references to gain unauthorized access.
Recommendations For version 2.1.4, consider restricting access to sensitive objects and implementing proper access control mechanisms to prevent manipulation of request parameters or object references. As a temporary workaround, restrict access to the vulnerable access control module to minimize the risk of exploitation.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-3014

Affected Products

Tracing