An issue was identified in the Identity Security Cloud (ISC) Transform preview and IdentityProfile preview API endpoints that allowed an authenticated administrator to execute user-defined templates as part of attribute transforms which could allow remote code execution on the host.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-31909 | An issue was identified in the Identity Security Cloud (ISC) Transform preview and IdentityProfile preview API endpoints that allowed an authenticated administrator to execute user-defined templates as part of attribute transforms which could allow remote code execution on the host. |
Fixes
Solution
This issue has been resolved. No further action is needed.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.sailpoint.com/security-advisories/ |
|
History
No history.
Status: PUBLISHED
Assigner: SailPoint
Published:
Updated: 2024-08-16T15:01:04.733Z
Reserved: 2024-04-04T16:14:54.310Z
Link: CVE-2024-3319
Updated: 2024-08-01T20:05:08.511Z
Status : Awaiting Analysis
Published: 2024-05-15T16:15:11.170
Modified: 2024-11-21T09:29:23.250
Link: CVE-2024-3319
No data.
OpenCVE Enrichment
No data.
EUVD