Description
ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation. A Tenant Administrator can obtain System Administrator dashboard access by modifying the scope via the scopes parameter.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-51041 | ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation. A Tenant Administrator can obtain System Administrator dashboard access by modifying the scope via the scopes parameter. |
References
History
Wed, 12 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-12T14:45:04.591Z
Reserved: 2023-02-23T00:00:00.000Z
Link: CVE-2022-48341
Updated: 2024-08-03T15:10:59.734Z
Status : Modified
Published: 2023-02-23T06:15:10.267
Modified: 2025-03-12T15:15:37.443
Link: CVE-2022-48341
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD