PT-2026-64184 · Owasp · Defectdojo
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OWASP DefectDojo version 2.59.0
Description
Improper privilege management occurs in the API/Web component within the
UserSerializer() function located in the dojo/api v2/serializers.py file. A remote attacker can manipulate the is staff argument to gain unauthorized privileges.Recommendations
Upgrade to version 2.58.3 or 3.0.0.
Exploit
Fix
Improper Privilege Management
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Defectdojo