You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{message }}
vantage6 vulnerable to Improper Preservation of Permissions
High severity GitHub Reviewed Published Feb 28, 2023 in vantage6/vantage6 • Updated Nov 18, 2024
Assigning existing users to a different organization is currently possible. It may lead to unintended access: if a user from organization A is accidentally assigned to organization B, they will retain their permissions and therefore might be able to access stuff they should not be allowed to access.
Patches
Update to 3.8.0
Workarounds
None
References
None
For more information
If you have any questions or comments about this advisory:
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended. Learn more on MITRE.
Impact
Assigning existing users to a different organization is currently possible. It may lead to unintended access: if a user from organization A is accidentally assigned to organization B, they will retain their permissions and therefore might be able to access stuff they should not be allowed to access.
Patches
Update to 3.8.0
Workarounds
None
References
None
For more information
If you have any questions or comments about this advisory:
References