CVE-2024-3319

An issue was identified in the Identity Security Cloud (ISC) Transform preview and IdentityProfile preview API endpoints that allowed an authenticated administrator to execute user-defined templates as part of attribute transforms which could allow remote code execution on the host.
Configurations

No configuration.

History

21 Nov 2024, 09:29

Type Values Removed Values Added
References () https://www.sailpoint.com/security-advisories/ - () https://www.sailpoint.com/security-advisories/ -
Summary
  • (es) Se identificó un problema en los endpoints de la API de vista previa de Transform de Identity Security Cloud (ISC) y de vista previa de IdentityProfile que permitían que un administrador autenticado ejecutara plantillas definidas por el usuario como parte de las transformaciones de atributos, lo que podría permitir la ejecución remota de código en el host.

15 May 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-15 16:15

Updated : 2024-11-21 09:29


NVD link : CVE-2024-3319

Mitre link : CVE-2024-3319

CVE.ORG link : CVE-2024-3319


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')