CVE Vulnerabilities

CVE-2020-29538

Published: Jan 29, 2021 | Modified: Nov 21, 2024
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Archer before 6.9 P1 (6.9.0.1) contains an improper access control vulnerability in an API. A remote authenticated malicious administrative user can potentially exploit this vulnerability to gather information about the system, and may use this information in subsequent attacks.

Affected Software

NameVendorStart VersionEnd Version
ArcherRsa6.6 (including)6.6.0.8 (excluding)
ArcherRsa6.7 (including)6.7.0.8 (excluding)
ArcherRsa6.8 (including)6.8.0.5 (excluding)
ArcherRsa6.9 (including)6.9.0.1 (excluding)

References