High severity8.8NVD Advisory· Published Jun 2, 2019· Updated Jun 17, 2026
CVE-2017-18376
CVE-2017-18376
Description
An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write access to escalate their privileges to the administrator's privileges. This affects app/controllers/UserCtrl.scala.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- TheHive/TheHivedescription
- Range: <2.13.4, <3.3.1
Patches
Vulnerability mechanics
References
3- github.com/TheHive-Project/TheHive/issues/408nvdPatchThird Party Advisory
- github.com/TheHive-Project/TheHive/releases/tag/3.3.1nvdThird Party Advisory
- gist.github.com/RaJiska/c1b4521aefd77ed43b06045ca05e2591nvd
News mentions
0No linked articles in our index yet.