An improper authorization vulnerability in the Palo Alto Networks Cortex XSOAR server enables an authenticated network-based attacker with investigation read permissions to download files from incident investigations of which they are aware but are not a part of. This issue impacts: All Cortex XSOAR 5.5.0 builds; Cortex XSOAR 6.1.0 builds earlier than 12099345. This issue does not impact Cortex XSOAR 6.2.0 versions.
Fixes

Solution

This issue is fixed in Cortex XSOAR 6.1.0 build 12099345 and all later Cortex XSOAR versions. There are currently no Cortex XSOAR 5.5.0 updates available for this issue.


Workaround

There are no known workarounds for this issue.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2024-09-16T20:58:16.361Z

Reserved: 2021-01-06T00:00:00

Link: CVE-2021-3049

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-09-08T17:15:11.423

Modified: 2024-11-21T06:20:50.837

Link: CVE-2021-3049

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.