Lucene search

K
cve[email protected]CVE-2023-39438
HistoryAug 15, 2023 - 5:15 p.m.

CVE-2023-39438

2023-08-1517:15:12
CWE-863
CWE-424
CWE-862
web.nvd.nist.gov
2385
authorization
cla-assistant
api
security
nvd
github

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

7.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.6%

A missing authorization check allows an arbitrary authenticated user to perform certain operations through the API of CLA-assistant by executing specific additional steps. This allows an arbitrary authenticated user to read CLA information including information of the persons who signed them as well as custom fields the CLA requester had configured. In addition, an arbitrary authenticated user can update or delete the CLA-configuration for repositories or organizations using CLA-assistant. The stored access tokens for GitHub are not affected, as these are redacted from the API-responses.

Affected configurations

NVD
Node
sapcontributor_license_agreement_assistantRange<2.13.1

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "CLA Assistant",
    "vendor": "SAP_SE",
    "versions": [
      {
        "status": "affected",
        "version": "<= 2.13.0"
      }
    ]
  }
]

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

7.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.6%

Related for CVE-2023-39438