Insecure Permissions in DTStack Taier API Revealing Sensitive Information
CVE-2023-29860
7.5HIGH
What is CVE-2023-29860?
The DTStack Taier version 1.3.0 has a vulnerability stemming from insecure permissions in the /Taier/API/tenant/listTenant interface. This flaw allows attackers to exploit the getCookie method, potentially leading to the exposure of sensitive information. Proper access controls and secure coding practices are essential to mitigate such vulnerabilities and protect user data.
