Lucene search

K
gitlabHttps://gitlab.com/gitlab-org/security-products/gemnasium-dbGITLAB-16E181392491B212B66852C57D2B6F36
HistoryMar 27, 2023 - 12:00 a.m.

Incorrect Permission Assignment for Critical Resource

2023-03-2700:00:00
https://gitlab.com/gitlab-org/security-products/gemnasium-db
gitlab.com
8
permission assignment
critical resource
vulnerability
opengoofy hippo4j
sensitive information
configverifycontroller
tenant management module
software

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

25.0%

Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker to obtain sensitive information via the ConfigVerifyController function of the Tenant Management module.

Affected configurations

Vulners
Node
mavenhippo4j-allRange1.4.3
VendorProductVersionCPE
mavenhippo4j-all*cpe:2.3:a:maven:hippo4j-all:*:*:*:*:*:*:*:*

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

25.0%

Related for GITLAB-16E181392491B212B66852C57D2B6F36