CVE-2024-52313

An authenticated data.all user is able to manipulate a getDataset query to fetch additional information regarding the parent Environment resource that the user otherwise would not able to fetch by directly querying the object via getEnvironment in data.all.
Configurations

No configuration.

History

12 Nov 2024, 13:56

Type Values Removed Values Added
Summary
  • (es) Un usuario autenticado de data.all puede manipular una consulta getDataset para obtener información adicional sobre el recurso Environment principal que de otro modo no podría obtener consultando directamente el objeto a través de getEnvironment en data.all.

09 Nov 2024, 02:15

Type Values Removed Values Added
References
  • () https://github.com/data-dot-all/dataall/security/advisories/GHSA-hx8q-7wxv-6c7c -

09 Nov 2024, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-09 01:15

Updated : 2024-11-12 13:56


NVD link : CVE-2024-52313

Mitre link : CVE-2024-52313

CVE.ORG link : CVE-2024-52313


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization