Avantra Server 24.x before 24.0.7 and 24.1.x before 24.1.1 mishandles the security of dashboards, aka XAN-5367. If a user can create a dashboard with an auto-login user, data disclosure may occur. Access control can be bypassed when there is a shared dashboard, and its auto-login user has privileges that a dashboard visitor should not have.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T02:51:11.474Z
Reserved: 2024-05-05T00:00:00
Link: CVE-2024-34519
Updated: 2024-08-02T02:51:11.474Z
Status : Awaiting Analysis
Published: 2024-05-05T22:15:07.563
Modified: 2024-11-21T09:18:51.220
Link: CVE-2024-34519
No data.
OpenCVE Enrichment
No data.
Weaknesses