7.4

CVE-2024-53348

LoxiLB v.0.9.7 and before is vulnerable to Incorrect Access Control which allows attackers to obtain sensitive information and escalate privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Loxilb ≫ Loxilb Version <= 0.9.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.243
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.4 2.2 5.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://github.com/loxilb-io/loxilb
Product
https://gist.github.com/HouqiyuA/8c734c849c1a9b69ac96c46eba4acbcb
Third Party Advisory