Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33193
HistoryDec 07, 2021 - 8:22 a.m.

Privilege Escalation

2021-12-0708:22:30
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
privilege escalation
invenio_drafts_resources
authenticated user
rest api
improper permission checks

EPSS

0.001

Percentile

21.4%

invenio_drafts_resources is vulnerability to privilege escalation. An authenticated user is able to publish draft records of other users via REST API calls when they know the record identifier and the draft validates due to improper permission checks.

EPSS

0.001

Percentile

21.4%

Related for VERACODE:33193