Impact
IRIS through version 2.4.29 has a flaw in the comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. The system does not properly enforce case authorization, allowing an attacker who has access to any single case to iterate through sequential object identifiers and read the comment threads of other cases for which the attacker has no legitimate permission. This results in the unauthorized disclosure of potentially sensitive information, compromising the confidentiality of remarks and evidence stored within the platform.
Affected Systems
The affected product is dfir-iris iris-web running versions up to and including 2.4.29. The vulnerability is present in any deployment of the web application that has not applied a post‑2.4.29 update.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity vulnerability; however, the EPSS score is below 1%, suggesting the probability of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an attacker to possess the credentials or session for at least one case, after which they can enumerate object IDs and access comment data from unauthorized cases. No known public exploit has been reported, but the lack of proper authorization checks makes discovery straightforward for privileged users with access to any case.
OpenCVE Enrichment