2025-03-23 03:03:54 +00:00

64 lines
2.2 KiB
JSON

{
"id": "CVE-2024-8183",
"sourceIdentifier": "security@huntr.dev",
"published": "2025-03-20T10:15:41.370",
"lastModified": "2025-03-20T10:15:41.370",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A CORS (Cross-Origin Resource Sharing) misconfiguration in prefecthq/prefect version 2.20.2 allows unauthorized domains to access sensitive data. This vulnerability can lead to unauthorized access to the database, resulting in potential data leaks, loss of confidentiality, service disruption, and data integrity risks."
},
{
"lang": "es",
"value": "Una configuraci\u00f3n incorrecta de CORS (Cross-Origin Resource Sharing) en prefecthq/prefect versi\u00f3n 2.20.2 permite que dominios no autorizados accedan a datos confidenciales. Esta vulnerabilidad puede provocar acceso no autorizado a la base de datos, lo que puede provocar fugas de datos, p\u00e9rdida de confidencialidad, interrupciones del servicio y riesgos para la integridad de los datos."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "security@huntr.dev",
"type": "Secondary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L",
"baseScore": 7.6,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"availabilityImpact": "LOW"
},
"exploitabilityScore": 2.8,
"impactScore": 4.7
}
]
},
"weaknesses": [
{
"source": "security@huntr.dev",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-346"
}
]
}
],
"references": [
{
"url": "https://github.com/prefecthq/prefect/commit/a69266e077169b8a32ad76b1dd3ea63b96d011c2",
"source": "security@huntr.dev"
},
{
"url": "https://huntr.com/bounties/b801de43-ff9f-4db9-b583-4797d4f7d3d2",
"source": "security@huntr.dev"
}
]
}