CVE-2024-50967 Information

Description

The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability. An attacker can remotely access this endpoint without authentication leading to unauthorized disclosure of sensitive information.

Reference

https://datagerry.readthedocs.io/en/latest/api/rest/user-management.html#rights https://github.com/0xByteHunter/CVE-2024-50967 https://medium.com/@0xbytehunter/my-first-cve-discovery-of-broken-access-control-in-the-datagerry-platform-7b0404f88a43

Share on: