Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:48412
HistoryAug 08, 2024 - 3:50 a.m.

Incorrect Permission Assignment

2024-08-0803:50:09
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
3
pulp
vulnerability
incorrect permission assignment
autoaddobjpermsmixin
unauthorized access
privileges
oldest user

CVSS3

8.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

AI Score

7

Confidence

High

EPSS

0.001

Percentile

31.3%

Pulp is vulnerable to Incorrect Permission Assignment. The vulnerability is due to the use of the AutoAddObjPermsMixin method, which sets permissions based on the oldest user with task permissions. This allows an attacker to gain unauthorized access or privileges, as the permissions for objects created in tasks are assigned to the oldest user with task permissions instead of the actual creator.

CVSS3

8.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

AI Score

7

Confidence

High

EPSS

0.001

Percentile

31.3%