Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-28248 | A Broken Access Control vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, and 5.4.0 before 5.4.10 allows remote, authenticated, and unprivileged users to retrieve alerts, cases, logs, observables, or tasks, regardless of the user's permissions, through a specific API endpoint. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 23 May 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 23 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Broken Access Control vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, and 5.4.0 before 5.4.10 allows remote, authenticated, and unprivileged users to retrieve alerts, cases, logs, observables, or tasks, regardless of the user's permissions, through a specific API endpoint. | |
| Weaknesses | CWE-266 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-23T21:19:24.490Z
Reserved: 2025-05-23T00:00:00.000Z
Link: CVE-2025-48741
Updated: 2025-05-23T21:19:20.270Z
Status : Awaiting Analysis
Published: 2025-05-23T20:15:25.763
Modified: 2025-05-28T14:58:52.920
Link: CVE-2025-48741
No data.
OpenCVE Enrichment
Updated: 2025-06-24T09:44:17Z
EUVD