Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46700
HistoryApr 30, 2024 - 11:35 a.m.

Authorization Bypass

2024-04-3011:35:35
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
authorization bypass
software vulnerability
property permissions

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

7

Confidence

Low

EPSS

0.01

Percentile

83.8%

roundup is vulnerable to Authorization Bypass. The vulnerability is due to improper property permissions checks, allowing unauthorized manipulation or access to restricted properties through certain methods.

References

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

7

Confidence

Low

EPSS

0.01

Percentile

83.8%