PT-2026-94046 · Opencv · Opencv
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenCVE versions 2.4.0 through 3.0.x
Description
An issue exists where the organizations API endpoint is not properly scoped to the organization associated with the token. Instead, it returns the memberships of the token creator. This allows attackers using organization-scoped tokens to list and retrieve all organizations the creator belongs to, bypassing token isolation boundaries.
Recommendations
Update OpenCVE to version 3.1.0 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opencv