60 lines
1.9 KiB
JSON
Raw Normal View History

{
"id": "CVE-2024-9431",
"sourceIdentifier": "security@huntr.dev",
"published": "2025-03-20T10:15:48.827",
"lastModified": "2025-03-20T10:15:48.827",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In version v0.0.14 of transformeroptimus/superagi, there is an improper privilege management vulnerability. After logging into the system, users can change the passwords of other users, leading to potential account takeover."
},
{
"lang": "es",
"value": "En la versi\u00f3n v0.0.14 de transformeroptimus/superagi, existe una vulnerabilidad de gesti\u00f3n de privilegios incorrecta. Tras iniciar sesi\u00f3n en el sistema, los usuarios pueden cambiar las contrase\u00f1as de otros usuarios, lo que podr\u00eda provocar el robo de cuentas."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "security@huntr.dev",
"type": "Secondary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "security@huntr.dev",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-269"
}
]
}
],
"references": [
{
"url": "https://huntr.com/bounties/9b33d7c1-ed0a-4f5b-a378-694570fd990b",
"source": "security@huntr.dev"
}
]
}