Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write access to escalate their privileges to the administrator's privileges. This affects app/controllers/UserCtrl.scala.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TheHive 权限许可和访问控制问题漏洞
Vulnerability Description
TheHive是一套可扩展的开源安全事件响应平台。 TheHive 2.13.4之前版本和3.3.1之前的3.x版本中的User API存在权限许可和访问控制问题漏洞。该漏洞源于网络系统或产品缺乏有效的权限许可和访问控制措施。
CVSS Information
N/A
Vulnerability Type
N/A