Impact
TheHive, up to version 4.1.24, suffers from a broken object‑level authorization flaw in its attachment download endpoints. The missing organization‑scoped check allows any authenticated user to request a content‑hash identifier and retrieve attachments that belong to other organizations. This flaw can lead to the disclosure of sensitive documents and potentially other data that could be attached to those files. The weakness is classified as CWE‑639, reflecting a failure to enforce proper access control on resources.
Affected Systems
TheHive 4.1.24 and earlier versions of the platform, maintained by TheHive‑Project. The vulnerability is limited to the attachment download API exposed by the AttachmentSrv component.
Risk and Exploitability
The severity is moderate, with a CVSS score of 7.1, yet the EPSS score is reported as less than 1%, suggesting a low likelihood of exploitation in the wild. The vulnerability requires authentication, but an attacker who has legitimate login credentials can abuse the missing check by supplying a valid content‑hash. No widely available exploit has been disclosed, and the issue is not listed in the CISA KEV catalogue.
OpenCVE Enrichment