Description
QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application.
No analysis available yet.
Remediation
Vendor Solution
The reported vulnerabilities are fixed in the latest version of the affected product.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-53992 | QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application. |
References
History
Thu, 19 Sep 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-09-19T20:24:32.988Z
Reserved: 2023-08-02T11:53:07.244Z
Link: CVE-2023-4102
Updated: 2024-08-02T07:17:11.861Z
Status : Modified
Published: 2023-10-03T12:15:11.040
Modified: 2024-11-21T08:34:23.777
Link: CVE-2023-4102
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD