Impact
The vulnerability resides in the file-center module of the microservices-platform, specifically the DELETE /files/{id} endpoint. The endpoint performs no ownership validation, allowing an attacker who is authenticated to delete any file belonging to another user. This results in loss of data integrity and availability for affected files and associated metadata, with potential cascading effects on applications relying on those files.
Affected Systems
zlt2000 microservices-platform, versions up to and including 6.0.0, is affected by this authorization bypass. No further version information is provided by the CNA.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity, though the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at the present time. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires valid user credentials for the target system; attackers can enumerate file identifiers through GET /files and then issue DELETE requests with those identifiers to remove files of other users.
OpenCVE Enrichment