PT-2023-20659 · Cerebrate · Cerebrate
CVE-2023-26468
·
Publicado
2023-02-23
·
Atualizado
2023-03-03
CVSS v3.1
9.1
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Cerebrate version 1.12
Description
The issue arises from the improper consideration of
organisation id during the creation of API keys. This could potentially lead to unauthorized access or misuse of API keys.Recommendations
For Cerebrate version 1.12, consider restricting access to API key creation until a proper fix is implemented to correctly handle
organisation id. As a temporary workaround, manually verify the organisation id for each API key created to ensure it aligns with the intended organization.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cerebrate