CVE-2023-49112

June 20, 2024, 4:07 p.m.

Product(s) Impacted

Kiuwan SAST

Description

Kiuwan provides an API endpoint /saas/rest/v1/info/application to get information about any application, providing only its name via the "application" parameter. This endpoint lacks proper access control mechanisms, allowing other authenticated users to read information about applications, even though they have not been granted the necessary rights to do so. This issue affects Kiuwan SAST: <master.1808.p685.q13371

Weaknesses

Date

Published: June 20, 2024, 1:15 p.m.

Last Modified: June 20, 2024, 4:07 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

551230f0-3615-47bd-b7cc-93e92e730bbf

References

https://r.sec-consult.com/kiuwan
551230f0-3615-47bd-b7cc-93e92e730bbf