A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user with valid login credentials to elevate privileges beyond the initially assigned roles.
The issue is resolved by upgrading to StreamPipes 0.92.0.
Metrics
Affected Vendors & Products
References
History
Wed, 09 Oct 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2023-06-23T07:07:42.875Z
Updated: 2024-10-09T15:11:39.555Z
Reserved: 2023-04-28T19:12:18.352Z
Link: CVE-2023-31469
Vulnrichment
Updated: 2024-08-02T14:53:30.748Z
NVD
Status : Modified
Published: 2023-06-23T08:15:09.220
Modified: 2024-11-21T08:01:55.840
Link: CVE-2023-31469
Redhat
No data.