PT-2024-13678 · Unknown · Kiuwan Sast

·

CVE-2023-49112

·

Published

2024-06-20

·

Updated

2024-07-03

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kiuwan SAST version <master.1808.p685.q13371>
Description The issue concerns an API endpoint "/saas/rest/v1/info/application" that allows access to information about any application, using the application parameter. This endpoint lacks proper access control, enabling other authenticated users to read application information without the necessary rights.
Recommendations For Kiuwan SAST version <master.1808.p685.q13371>, consider restricting access to the "/saas/rest/v1/info/application" API endpoint until a proper fix is available. As a temporary workaround, limit the use of the application parameter in this endpoint to minimize the risk of unauthorized access.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-49112

Affected Products

Kiuwan Sast