CVE-2023-35937
Metersphere missing permission check
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6EPSS 0.6%KEV nãoPoC —Patch —
Lifecycle
Jul 06, 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Metersphere is an open source continuous testing platform. In versions prior to 2.10.2 LTS, some key APIs in Metersphere lack permission checks. This allows ordinary users to execute APIs that can only be executed by space administrators or project administrators. For example, ordinary users can be updated as space administrators. Version 2.10.2 LTS has a patch for this issue.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L
Affected products
metersphere · metersphereWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →