5

CVE-2011-4311

ResourceSpace before 4.2.2833 does not properly validate access keys, which allows remote attackers to bypass intended resource restrictions via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MontalaResourcespace Version <= 4.2.2816
MontalaResourcespace Version2.2.1240
MontalaResourcespace Version2.3.1374
MontalaResourcespace Version3.0.1490
MontalaResourcespace Version3.1.1557
MontalaResourcespace Version3.2.1651
MontalaResourcespace Version3.3.1723
MontalaResourcespace Version3.4.1794
MontalaResourcespace Version3.5.1857
MontalaResourcespace Version3.6.2022
MontalaResourcespace Version3.7.2088
MontalaResourcespace Version3.8.2144
MontalaResourcespace Version3.9.2269
MontalaResourcespace Version4.0.2429
MontalaResourcespace Version4.1.2567
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.361
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.