CVE-2023-49112

Kiuwan provides an API endpoint

/saas/rest/v1/info/application

to get information about any 
application, providing only its name via the "application" parameter. This endpoint lacks proper access 
control mechanisms, allowing other authenticated users to read 
information about applications, even though they have not been granted 
the necessary rights to do so.



This issue affects Kiuwan SAST: <master.1808.p685.q13371
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
SEC-VLabCNA
---
---
CISA-ADPADP
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVEADP
---
---