Impact
Corteza application versions up to 2024.9.10 allow attackers to download private attachment files without authentication by specifying certain URL kind segments. The vulnerability is an improper authorization flaw (CWE‑863) that permits a lack of permission checks on the compose attachment endpoints. When an attacker knows the identifier of a private record or module attachment, they can request the original or preview route without needing a valid token or signature, thereby exposing files that cross namespace and record permissions.
Affected Systems
The affected product is Corteza, the open‑source business applications platform. Versions released through 2024.9.10 contain the flaw; any installation deploying those versions is susceptible.
Risk and Exploitability
The CVSS score of 8.2 reflects a high severity confidentiality impact, and attackers can exploit the flaw over the public network by sending unauthenticated HTTP requests. The EPSS score is not available, and the vulnerability is not listed in the KEV catalog, but the lack of authentication makes the attack likely if the application is exposed. Based on the description, it is inferred that attackers can discover attachment identifiers through enumeration or guessing, which is all that is required to retrieve the files.
OpenCVE Enrichment