CVE-2024-6322
CVE-2024-6322
Título es
CVE-2024-6322
Mar, 20/08/2024 – 18:15
Tipo
CWE-266
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-6322
Descripción en
Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as the ReqActions check was not scoped to each specific datasource. The account must have prior query access to the impacted datasource.
20/08/2024
20/08/2024
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:L
Gravedad 3.1 (CVSS 3.1 Base Score)
4.40
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
MEDIUM
Enviar en el boletín
Off