CVE-2021-38616
07.09.2021, 12:15
In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/user/{user-guid}/ user edition endpoint could permit any logged-in user to increase their own permissions via a user_permissions array in a PATCH request. A guest user could modify other users' profiles and much more.Enginsight
Vendor | Product | Version |
---|---|---|
eigentech | natural_language_processing | 3.10.1 |
𝑥
= Vulnerable software versions