VYPR
Unrated severityNVD Advisory· Published Aug 9, 2023· Updated Aug 2, 2024

Information disclosure via the debug function in assertions in Guardian/CMC before 22.6.2

CVE-2023-24471

Description

An access control vulnerability was found, due to the restrictions that are applied on actual assertions not being enforced in their debug functionality.

An authenticated user with reduced visibility can obtain unauthorized information via the debug functionality, obtaining data that would normally be not accessible in the Query and Assertions functions.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.