CVE-2024-49202

Keyfactor Command before 12.5.0 has Incorrect Access Control: access tokens are over permissioned, aka 64099. The fixed versions are 11.5.1.1, 11.5.2.1, 11.5.3.1, 11.5.4.5, 11.5.6.1, 11.6.0, 12.2.0.1, 12.3.0.1, 12.4.0.1, 12.5.0, and 24.4.0.
Configurations

No configuration.

History

21 Dec 2024, 00:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.6
CWE CWE-276
Summary
  • (es) El comando Keyfactor anterior a la versión 12.5.0 tiene un control de acceso incorrecto: los tokens de acceso tienen más permisos que los permitidos, es decir, 64099. Las versiones corregidas son 11.5.1.1, 11.5.2.1, 11.5.3.1, 11.5.4.5, 11.5.6.1, 11.6.0, 12.2.0.1, 12.3.0.1, 12.4.0.1, 12.5.0 y 24.4.0.

18 Dec 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-18 19:15

Updated : 2024-12-21 00:15


NVD link : CVE-2024-49202

Mitre link : CVE-2024-49202

CVE.ORG link : CVE-2024-49202


JSON object : View

Products Affected

No product.

CWE
CWE-276

Incorrect Default Permissions