Impact
An unauthorized access flaw exists in the Benchmark/Engagement/Product/Survey component of OWAP DefectDojo versions through 2.55.4. The flaw stems from an unknown functionality that can be manipulated remotely, allowing an attacker to bypass normal authorization checks. The vulnerability aligns with CWE‑285 (Incorrect Authorization) and CWE‑639 (Privilege Escalation), meaning an attacker who can exploit it gains higher privileges and can perform actions they should not be permitted to. The description explicitly states that the exploit has been publicly disclosed and may be used.
Affected Systems
The affected vendor is OWAP:DefectDojo. Users running DefectDojo 2.55.4 or earlier are impacted. Upgrading to version 2.56.0 removes the flaw. No other affected versions are listed in the CVE data.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate severity. EPSS is not available, but the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, with no local or physical access prerequisites. An attacker who crafts the appropriate manipulation can directly reach the component and bypass authorization, which could lead to unauthorized data access or modification on the impacted systems.
OpenCVE Enrichment