PT-2023-23085 · Unknown · Foundry Comments

CVE-2023-30956

·

Publicado

2023-07-10

·

Atualizado

2023-07-18

CVSS v3.1

5.3

Média

VetorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Foundry Comments versions prior to 2.267.0
Description A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if they knew the internal UUID of the target attachment.
Recommendations For versions prior to 2.267.0, update to Foundry Comments 2.267.0 to resolve the issue. As a temporary workaround, consider restricting access to attachments or limiting the information that can be discovered through the internal UUID of the target attachment until the update is applied.

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-30956

Produtos afetados

Foundry Comments