Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37673
HistoryOct 24, 2022 - 2:17 p.m.

Improper Access Control

2022-10-2414:17:50
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7
improper access control
safepickle.py
authentication bypass
software

EPSS

0.002

Percentile

57.3%

shinken is vulnerable to improper access control. The vulnerability is due the find_class function in safepickle.py unserializing objects passed from nodes to the server which allows an attacker to bypass authentication.

EPSS

0.002

Percentile

57.3%