In OpenCTI through 5.2.4, a broken access control vulnerability has been identified in the profile endpoint. An attacker can abuse the identified vulnerability in order to arbitrarily change their registered e-mail address as well as their API key, even though such action is not possible through the interface, legitimately.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-07-05T12:43:40
Updated: 2024-08-03T06:48:34.859Z
Reserved: 2022-05-04T00:00:00
Link: CVE-2022-30290
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-07-05T13:15:08.427
Modified: 2024-11-21T07:02:30.720
Link: CVE-2022-30290
Redhat
No data.