Due to inconsistent authorization permissions, data.all may allow an external actor with an authenticated account to perform restricted operations against DataSets and Environments.
References
Configurations
No configuration.
History
12 Nov 2024, 13:56
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
09 Nov 2024, 02:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
09 Nov 2024, 01:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-09 01:15
Updated : 2024-11-12 13:56
NVD link : CVE-2024-52312
Mitre link : CVE-2024-52312
CVE.ORG link : CVE-2024-52312
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization