eLabFTW is an open source electronic lab notebook for research labs. An incorrect permission check has been found that could allow an authenticated user to access several kinds of otherwise restricted information. If anonymous access is allowed (something disabled by default), this extends to anyone. Users are advised to upgrade to at least version 5.1.0. System administrators can disable anonymous access in the System configuration panel.
History

Tue, 01 Oct 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Elabftw
Elabftw elabftw
CPEs cpe:2.3:a:elabftw:elabftw:*:*:*:*:*:*:*:*
Vendors & Products Elabftw
Elabftw elabftw
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Oct 2024 15:00:00 +0000

Type Values Removed Values Added
Description eLabFTW is an open source electronic lab notebook for research labs. An incorrect permission check has been found that could allow an authenticated user to access several kinds of otherwise restricted information. If anonymous access is allowed (something disabled by default), this extends to anyone. Users are advised to upgrade to at least version 5.1.0. System administrators can disable anonymous access in the System configuration panel.
Title eLabFTW contains a direct and indirect information disclosure
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-10-01T14:53:48.085Z

Updated: 2024-10-01T15:12:46.615Z

Reserved: 2024-08-28T20:21:32.804Z

Link: CVE-2024-45408

cve-icon Vulnrichment

Updated: 2024-10-01T15:12:38.838Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-01T15:15:08.220

Modified: 2024-10-04T13:51:25.567

Link: CVE-2024-45408

cve-icon Redhat

No data.