CVE-2024-52313

An authenticated data.all user is able to manipulate a getDataset query to fetch additional information regarding the parent Environment resource that the user otherwise would not able to fetch by directly querying the object via getEnvironment in data.all.
Configurations

No configuration.

History

No history.

Information

Published : 2024-11-09 01:15

Updated : 2024-11-12 13:56


NVD link : CVE-2024-52313

Mitre link : CVE-2024-52313

CVE.ORG link : CVE-2024-52313


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization