Advisory ID: LVD-2024-010
CVSSv 4.0 Vector: AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
CVSSv 4.0 Base Score: 7.7
Severity: High
CVE: CVE-2024-48953
CWE: CWE-288
Date Published: 2024-10-02
Description:
Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users to register their own authentication plugins in Logpoint, resulting in unauthorized access.
Affected Product:
Logpoint versions prior to 7.5.0.
Solution:
Upgrade to Logpoint v7.5.0.
Acknowledgments:
Mehmet D. Ince
Sr. Vulnerability Researcher
Comments
Article is closed for comments.