Unauthorized Access to Job Processing Metadata in ISC Message Server API
CVE-2024-3317
6.5MEDIUM
What is CVE-2024-3317?
An improper access control was identified in the Identity Security Cloud (ISC) message server API that allowed an authenticated user to exfiltrate job processing metadata (opaque messageIDs, work queue depth and counts) for other tenants.
Affected Version(s)
Identity Security Cloud