Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25425
HistoryMay 15, 2020 - 1:24 a.m.

Privilege Escalation

2020-05-1501:24:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.002 Low

EPSS

Percentile

53.5%

ruby is vulnerable to privilege escalation. The check_privileges method in vmdb/app/controllers/application_controller.rb allows authenticated users to bypass authorization and gain higher privileges due to improper RBAC checking.

0.002 Low

EPSS

Percentile

53.5%

Related for VERACODE:25425