CVE-2024-52313
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2024-52313 is a vulnerability affecting the data.all API where an authenticated user with the data.all role can manipulate getDataset queries to access additional information on the parent Environment resource, beyond what they would be able to access through the standard getEnvironment function. This issue expands the scope of data that authenticated users can retrieve, potentially leading to unintended data disclosure or unauthorized access. It is essential for API users and administrators to implement access controls and monitor API activity to mitigate the risks associated with this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.