Impact
PatrowlManager versions up to 1.8.4 contain a weakness in the events and alerts API that fails to enforce ownership checks. An authenticated attacker can read the event history of any user, delete arbitrary events, and modify alerts owned by other users. This flaw enables data leakage and tampering within the platform, effectively granting the attacker elevated authority over other accounts.
Affected Systems
The vulnerability affects Patrowl Manager 1.8.4 and earlier releases. It is specifically tied to the events and alerts API endpoints exposed by the application.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact to confidentiality, integrity, and availability. The EPSS score of less than 1% suggests current public exploitation is unlikely, and the vulnerability is not listed in the CISA KEV catalog. The attack vector requires a valid authenticated session; an attacker would need legitimate credentials or to gain them through other means. Once authenticated, the attacker can bypass authorization controls and perform actions normally protected by user ownership checks.
OpenCVE Enrichment