CVE-2024-45805

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Dec 26, 2024
Updated: Dec 27, 2024
CWE ID 285
CWE ID 200

Summary

CVE-2024-45805 is a vulnerability affecting OpenCTI, an open-source cyber threat intelligence platform. Prior to version 6.3.0, the platform failed to implement proper access controls, allowing general users to access support information that is typically restricted to admin and support users. This issue stems from the availability of UUIDs, which are unique identifiers associated with support files, to all users through a logs query. Consequently, unauthorized users could gain access to sensitive information. OpenCTI resolved this vulnerability in version 6.3.0 by enhancing access control measures for support information.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share