CVE-2024-10953

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Nov 9, 2024
Updated: Nov 12, 2024
CWE ID 863

Summary

CVE-2024-10953 is a new vulnerability that has been identified, allowing authenticated data.all users to execute mutating UPDATE operations on Notification records within data.all for groups they are not a member of. This issue poses a significant risk, as unintended modifications to group notifications can lead to confusion, misinformation, or even unintended actions. The impact of this vulnerability can range from minor inconvenience to major security incidents, depending on the specific use case and configuration of the affected system. It is recommended that affected organizations apply the necessary patches or workarounds as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share