Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46592
HistoryApr 23, 2024 - 6:24 p.m.

Authentication Bypass Via Spoofing

2024-04-2318:24:31
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7
apache hugegraph-api
authentication bypass
spoofing
vulnerability
insufficient authentication checks
attacker

CVSS3

0

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N

AI Score

7.1

Confidence

Low

EPSS

0

Percentile

9.0%

Apache HugeGraph-api is vulnerable to an Authentication Bypass via Spoofing. The vulnerability is due to insufficient authentication checks, allowing an attacker to bypass authentication by spoofing certain parameters or headers.

CVSS3

0

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N

AI Score

7.1

Confidence

Low

EPSS

0

Percentile

9.0%