Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to list all users in the system, including those from other organizations. This issue affects EZD RP: from 15 before 15.84, from 16 before 16.15, from 17 before 17.2.
Metrics
Affected Vendors & Products
References
History
Thu, 10 Oct 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-286 |
Fri, 23 Aug 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Nask
Nask ezd Rp |
|
Weaknesses | CWE-863 | |
CPEs | cpe:2.3:a:nask:ezd_rp:*:*:*:*:*:*:*:* | |
Vendors & Products |
Nask
Nask ezd Rp |
|
Metrics |
cvssV3_1
|
Wed, 07 Aug 2024 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 07 Aug 2024 11:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to list all users in the system, including those from other organizations. This issue affects EZD RP: from 15 before 15.84, from 16 before 16.15, from 17 before 17.2. | |
Title | Users listing in EZD RP | |
Weaknesses | CWE-286 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: CERT-PL
Published: 2024-08-07T10:58:47.839Z
Updated: 2024-10-10T15:36:22.892Z
Reserved: 2024-07-30T08:43:02.704Z
Link: CVE-2024-7266
Vulnrichment
Updated: 2024-08-07T13:08:30.566Z
NVD
Status : Modified
Published: 2024-08-07T11:15:46.077
Modified: 2024-10-10T16:15:08.910
Link: CVE-2024-7266
Redhat
No data.