CVE Vulnerabilities

CVE-2023-50267

Improper Privilege Management

Published: Dec 28, 2023 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

MeterSphere is a one-stop open source continuous testing platform. Prior to 2.10.10-lts, the authenticated attackers can update resources which dont belong to him if the resource ID is known. This issue if fixed in 2.10.10-lts. There are no known workarounds.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Metersphere Metersphere * 2.10.10 (excluding)

Potential Mitigations

References