Insufficient authentication in user account management in Yugabyte Platform allows local network attackers with a compromised user session to change critical security information without re-authentication. An attacker with user session and access to application can modify settings such as password and email without being prompted for the current password, enabling account takeover.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Yugabyte

Published:

Updated: 2024-08-13T20:45:30.139Z

Reserved: 2024-07-18T20:20:00.305Z

Link: CVE-2024-6895

cve-icon Vulnrichment

Updated: 2024-08-01T21:45:38.424Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-07-19T15:15:10.547

Modified: 2024-11-21T09:50:29.310

Link: CVE-2024-6895

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.