CVE Vulnerabilities

CVE-2023-50267

Improper Privilege Management

Published: Dec 28, 2023 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

MeterSphere is a one-stop open source continuous testing platform. Prior to 2.10.10-lts, the authenticated attackers can update resources which dont belong to him if the resource ID is known. This issue if fixed in 2.10.10-lts. There are no known workarounds.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
MetersphereMetersphere*2.10.10 (excluding)

Potential Mitigations

References