Description
As a manager, you should not be able to modify a series of settings. In the UI this is indeed hidden as a convenience for the role since most managers would not be savvy enough to modify these settings. They can use their token to still modify those settings though through a standard HTTP request

While this is not a critical vulnerability, it does indeed need to be patched to enforce the expected permission level.
Published: 2024-02-25
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-16234 As a manager, you should not be able to modify a series of settings. In the UI this is indeed hidden as a convenience for the role since most managers would not be savvy enough to modify these settings. They can use their token to still modify those settings though through a standard HTTP request While this is not a critical vulnerability, it does indeed need to be patched to enforce the expected permission level.
History

No history.

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2024-08-21T15:10:35.855Z

Reserved: 2024-01-11T19:54:59.182Z

Link: CVE-2024-0439

cve-icon Vulnrichment

Updated: 2024-08-01T18:04:49.767Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-02-26T16:27:50.490

Modified: 2024-11-21T08:46:35.647

Link: CVE-2024-0439

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses