CVE-2024-10953
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2024-10953 is a new vulnerability that has been identified, allowing authenticated data.all users to execute mutating UPDATE operations on Notification records within data.all for groups they are not a member of. This issue poses a significant risk, as unintended modifications to group notifications can lead to confusion, misinformation, or even unintended actions. The impact of this vulnerability can range from minor inconvenience to major security incidents, depending on the specific use case and configuration of the affected system. It is recommended that affected organizations apply the necessary patches or workarounds as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.