VYPR

Cla Assistant

by SAP

CVEs (2)

  • CVE-2023-39438HigAug 15, 2023
    risk 0.53cvss 8.1epss 0.00

    A missing authorization check allows an arbitrary authenticated user to perform certain operations through the API of CLA-assistant by executing specific additional steps. This allows an arbitrary authenticated user to read CLA information including information of the persons…

  • CVE-2021-21471MedJan 12, 2021
    risk 0.42cvss 6.5epss 0.01

    In CLA-Assistant, versions before 2.8.5, due to improper access control an authenticated user could access API endpoints which are not intended to be used by the user. This could impact the integrity of the application.