Non-Admin Access Vulnerability in Microcks
CVE-2024-44076

9.8CRITICAL

Key Information:

Vendor

Microcks

Status
Vendor
CVE Published:
19 August 2024

What is CVE-2024-44076?

A vulnerability exists in Microcks before version 1.10.0 that compromises access control mechanisms for its API. Specifically, the endpoints POST /api/import and POST /api/export can be accessed by non-administrator users, which could lead to unauthorized import or export operations. This issue highlights potential risks in service access management and underscores the importance of implementing strict authorization checks to prevent unauthorized activities on sensitive endpoints.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.