Description
A vulnerability has been identified in Mendix Applications using Mendix 10 (All versions < V10.11.0), Mendix Applications using Mendix 10 (V10.6) (All versions < V10.6.9), Mendix Applications using Mendix 9 (All versions >= V9.3.0 < V9.24.22). Affected applications could allow users with the capability to manage a role to elevate the access rights of users with that role. Successful exploitation requires to guess the id of a target role which contains the elevated access rights.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-31238 | A vulnerability has been identified in Mendix Applications using Mendix 10 (All versions < V10.11.0), Mendix Applications using Mendix 10 (V10.6) (All versions < V10.6.9), Mendix Applications using Mendix 9 (All versions >= V9.3.0 < V9.24.22). Affected applications could allow users with the capability to manage a role to elevate the access rights of users with that role. Successful exploitation requires to guess the id of a target role which contains the elevated access rights. |
References
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2024-09-06T17:00:43.293Z
Reserved: 2024-04-23T12:07:54.905Z
Link: CVE-2024-33500
Updated: 2024-08-02T02:36:03.343Z
Status : Deferred
Published: 2024-06-11T12:15:15.957
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-33500
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD