PT-2025-18314 · Opencti · Opencti

Itlabbet

·

Published

2025-04-30

·

Updated

2025-05-19

·

CVE-2025-24887

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions OpenCTI versions 6.4.8 through 6.4.9
Description The issue allows a user to bypass allow/deny lists and modify attributes that are intended to be unmodifiable. This includes toggling the external flag on/off, changing the own token value for a user, and editing attributes not in the allow list, such as otp qr and otp activated. If external users exist in the OpenCTI setup with sensitive identity information, this can be used to enumerate existing user accounts as a standard low-privileged user.
Recommendations For OpenCTI versions 6.4.8 through 6.4.9, update to version 6.4.10 to resolve the issue. As a temporary workaround, consider restricting access to the external flag and token value modification functionality until the update is applied. Additionally, limit editing capabilities for attributes not in the allow list, such as otp qr and otp activated, to minimize the risk of exploitation.

Exploit

Fix

LPE

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-24887
GHSA-8262-PW2Q-5QC3
PYSEC-2025-178

Affected Products

Opencti