Beveiligingsadvies

CVE-2018-1000875

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2018-12-20 17:00:00
Laatst bijgewerkt 2024-09-16 19:52:08
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

Berkeley Open Infrastructure for Network Computing BOINC Server and Website Code version 0.9-1.0.2 contains a CWE-302: Authentication Bypass by Assumed-Immutable Data vulnerability in Website Terms of Service Acceptance Page that can result in Access to any user account. This attack appear to be exploitable via Specially crafted URL. This vulnerability appears to have been fixed in 1.0.3.