PT-2026-49174 · Unknown · Huly Platform
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Huly Platform versions prior to 0.7.1
Description
Improper access controls in the RPC Interface component allow for remote attacks. The issue is located in the
getMailboxSecret() function within the server/account/src/operations.ts file.Recommendations
Update to a version later than 0.7.0.
As a temporary workaround, restrict access to the
getMailboxSecret() function.Fix
Incorrect Privilege Assignment
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Huly Platform