CVE-2021-383703.01.2022, 15:15openwhyd is vulnerable to Improper AuthorizationEnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST6.1 MEDIUMNETWORKLOWNONECVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N@huntrdevCNA8.6 HIGHLOCALLOWNONECVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HCVEADP------Base ScoreCVSS 3.xEPSS ScorePercentile: 34%VendorProductVersionopenwhydopenwhyd𝑥< 1.45.12𝑥= Vulnerable software versionsKnown Exploits!https://huntr.dev/bounties/d66f90d6-1b5f-440d-8be6-cdffc9d4587ehttps://huntr.dev/bounties/d66f90d6-1b5f-440d-8be6-cdffc9d4587eCommon Weakness EnumerationCWE-285 - Improper AuthorizationThe software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.Referenceshttps://github.com/openwhyd/openwhyd/commit/102a97bb082edc831cf35d27f9e5c4f55f10ae85https://huntr.dev/bounties/d66f90d6-1b5f-440d-8be6-cdffc9d4587ehttps://github.com/openwhyd/openwhyd/commit/102a97bb082edc831cf35d27f9e5c4f55f10ae85https://huntr.dev/bounties/d66f90d6-1b5f-440d-8be6-cdffc9d4587e