cve/2023/CVE-2023-49112.md

18 lines
868 B
Markdown
Raw Normal View History

2024-06-22 09:37:59 +00:00
### [CVE-2023-49112](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-49112)
![](https://img.shields.io/static/v1?label=Product&message=SAST&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
Kiuwan provides an API endpoint/saas/rest/v1/info/applicationto get information about any application, providing only its name via the "application" parameter. This endpoint lacks proper access control mechanisms, allowing other authenticated users to read information about applications, even though they have not been granted the necessary rights to do so.This issue affects Kiuwan SAST: <master.1808.p685.q13371
### POC
#### Reference
- https://r.sec-consult.com/kiuwan
#### Github
No PoCs found on GitHub currently.