Impact
CAPEv2 has a flaw where its REST API does not verify ownership of analysis tasks. As a result, any authenticated user can read or delete tasks created by other users. This flaw permits attackers to enumerate all tasks and remove valuable analysis results, compromising the confidentiality of analytic data and the integrity of the analysis repository.
Affected Systems
CAPEv2 from kevoreilly is affected. All installations that include commit 471ee4b or earlier and have not applied the subsequent fix that enforces ownership checks are vulnerable. No specific release numbers are listed in the data provided.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity, and the EPSS score is < 1%. The vulnerability is not listed in the CISA KEV catalog. Attack requires that the user is authenticated; a legitimate user can simply send requests to the task view and delete endpoints to enumerate and delete tasks. Because the check on ownership is missing, the impact is direct and can be executed without additional privileges.
OpenCVE Enrichment