Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to list all users in the system, including those from other organizations. This issue affects EZD RP: from 15 before 15.84, from 16 before 16.15, from 17 before 17.2.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 17 Mar 2025 09:45:00 +0000


Mon, 17 Mar 2025 08:45:00 +0000


Thu, 10 Oct 2024 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-286

Fri, 23 Aug 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Nask
Nask ezd Rp
Weaknesses CWE-863
CPEs cpe:2.3:a:nask:ezd_rp:*:*:*:*:*:*:*:*
Vendors & Products Nask
Nask ezd Rp
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Wed, 07 Aug 2024 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Aug 2024 11:00:00 +0000

Type Values Removed Values Added
Description Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to list all users in the system, including those from other organizations. This issue affects EZD RP: from 15 before 15.84, from 16 before 16.15, from 17 before 17.2.
Title Users listing in EZD RP
Weaknesses CWE-286
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/R:A/V:D/RE:L/U:Green'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2025-03-25T14:31:55.797Z

Reserved: 2024-07-30T08:43:02.704Z

Link: CVE-2024-7266

cve-icon Vulnrichment

Updated: 2024-08-07T13:08:30.566Z

cve-icon NVD

Status : Modified

Published: 2024-08-07T11:15:46.077

Modified: 2025-03-17T09:15:12.310

Link: CVE-2024-7266

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.