PT-2026-48812 · Devguard · Devguard
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
DevGuard versions prior to 1.4.2
Description
On API instances with public assets, any authenticated user can perform unauthorized write operations, regardless of their organization, project, or asset membership. This allows attackers to create, update, reapply, and delete VEX rules, as well as manage dependency-vuln events (including accept, reject, and mitigate decisions), batch event creation, vulnerability synchronization, mitigation, license risk creation, external reference writes, artifact creation, and license refreshes. This issue impacts the integrity of the vulnerability data for public assets, potentially allowing attackers to silence vulnerabilities or provide misleading justifications, which affects downstream consumers relying on
vex.json and sbom.json endpoints.Recommendations
Update to version 1.4.2.
As a temporary workaround, change the visibility of affected assets from public to private in the asset settings to restore correct authorization on write endpoints.
Exploit
Fix
Incorrect Authorization
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Devguard