2024-12-08 03:06:42 +00:00

68 lines
2.4 KiB
JSON

{
"id": "CVE-2024-48953",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-11-07T17:15:08.570",
"lastModified": "2024-11-08T19:01:03.880",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users to register their own authentication plugins in Logpoint, resulting in unauthorized access."
},
{
"lang": "es",
"value": "Se descubri\u00f3 un problema en Logpoint antes de la versi\u00f3n 7.5.0. Los endpoints para crear, editar o eliminar m\u00f3dulos de autenticaci\u00f3n de terceros carec\u00edan de las comprobaciones de autorizaci\u00f3n adecuadas. Esto permit\u00eda que los usuarios no autenticados registraran sus propios complementos de autenticaci\u00f3n en Logpoint, lo que daba lugar a un acceso no autorizado."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"attackVector": "ADJACENT_NETWORK",
"attackComplexity": "HIGH",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 1.6,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-306"
}
]
}
],
"references": [
{
"url": "https://docs.logpoint.com/docs/whats-new-in-logpoint/en/latest/",
"source": "cve@mitre.org"
},
{
"url": "https://servicedesk.logpoint.com/hc/en-us/articles/21968899128221-Authentication-Bypass-using-URL-endpoints-in-the-Authentication-Modules",
"source": "cve@mitre.org"
},
{
"url": "https://servicedesk.logpoint.com/hc/en-us/sections/7201103730845-Product-Security",
"source": "cve@mitre.org"
}
]
}