CVE-2024-52312

Due to inconsistent authorization permissions, data.all may allow an external actor with an authenticated account to perform restricted operations against DataSets and Environments.
Configurations

No configuration.

History

12 Nov 2024, 13:56

Type Values Removed Values Added
Summary
  • (es) Debido a permisos de autorización inconsistentes, data.all puede permitir que un actor externo con una cuenta autenticada realice operaciones restringidas contra conjuntos de datos y entornos.

09 Nov 2024, 02:15

Type Values Removed Values Added
References
  • () https://github.com/data-dot-all/dataall/security/advisories/GHSA-676j-g6g5-chj9 -

09 Nov 2024, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-09 01:15

Updated : 2024-11-12 13:56


NVD link : CVE-2024-52312

Mitre link : CVE-2024-52312

CVE.ORG link : CVE-2024-52312


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization