CVE-2019-18181
19.12.2019, 19:15
In CloudVision Portal all releases in the 2018.1 and 2018.2 Code train allows users with read-only permissions to bypass permissions for restricted functionality via CVP API calls through the Configlet Builder modules. This vulnerability can potentially enable authenticated users with read-only access to take actions that are otherwise restricted in the GUI.Enginsight
Vendor | Product | Version |
---|---|---|
arista | cloudvision_portal | 2018.1.0 ≤ 𝑥 ≤ 2018.1.4 |
arista | cloudvision_portal | 2018.2.0 ≤ 𝑥 ≤ 2018.2.3 |
𝑥
= Vulnerable software versions