CVE-2024-45805
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2024-45805 is a vulnerability affecting OpenCTI, an open-source cyber threat intelligence platform. Prior to version 6.3.0, the platform failed to implement proper access controls, allowing general users to access support information that is typically restricted to admin and support users. This issue stems from the availability of UUIDs, which are unique identifiers associated with support files, to all users through a logs query. Consequently, unauthorized users could gain access to sensitive information. OpenCTI resolved this vulnerability in version 6.3.0 by enhancing access control measures for support information.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- OpenCTI