An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write access to escalate their privileges to the administrators privileges. This affects app/controllers/UserCtrl.scala.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Thehive | Strangebee | * | 2.13.4 (excluding) |
Thehive | Strangebee | 3.0.0 (including) | 3.3.1 (excluding) |