Description
Pandora FMS v7.0NG.760 and below allows an improper access control in Configuration (Credential store) where a user with the role of Operator (Write) could create, delete, view existing keys which are outside the intended role.
No analysis available yet.
Remediation
Vendor Solution
Fixed in v761
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-30869 | Pandora FMS v7.0NG.760 and below allows an improper access control in Configuration (Credential store) where a user with the role of Operator (Write) could create, delete, view existing keys which are outside the intended role. |
References
History
Tue, 17 Sep 2024 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Access Control in Configuration (Credential store) | Improper Access Control in Configuration (Credential store) |
Status: PUBLISHED
Assigner: ARTICA
Published:
Updated: 2024-09-17T02:31:29.597Z
Reserved: 2022-02-28T00:00:00.000Z
Link: CVE-2022-26308
No data.
Status : Modified
Published: 2022-08-01T13:15:10.257
Modified: 2024-11-21T06:53:43.783
Link: CVE-2022-26308
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD