Skip to main content

Authorization Bypass Through User-Controlled Key

CVE-2024-10452

Severity Low
Score 2.1/10

Summary

Organisation admins can delete pending invites created in an organisation they are not part of. This issue affects versions through v10.4.12, v11.0.0-preview through v11.0.7, v11.1.0 through v11.1.8, v11.2.0 through v11.2.3+security-01 and v11.3.0 through v11.3.0+security-01.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • NONE
  • HIGH
  • NONE
  • NONE

CWE-639 - Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Advisory Timeline

  • Published