CVE-2017-18376
02.06.2019, 20:29
An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write access to escalate their privileges to the administrator's privileges. This affects app/controllers/UserCtrl.scala.Enginsight
Vendor | Product | Version |
---|---|---|
strangebee | thehive | 𝑥 < 2.13.4 |
strangebee | thehive | 3.0.0 ≤ 𝑥 < 3.3.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References