CVE-2024-28087
EUVD-2024-147715.05.2024, 17:15
In Bonitasoft runtime Community edition, the lack of dynamic permissions causes IDOR vulnerability. Dynamic permissions existed only in Subscription edition and have now been restored in Community edition, where they are not custmizable.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| bonitasoft | bonita_web | 𝑥 < 2024.2-u1 | ADP |
Common Weakness Enumeration
References