Beveiligingsadvies

CVE-2019-12782

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2019-07-09 15:20:44
Laatst bijgewerkt 2024-08-04 23:32:55
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

An authorization bypass vulnerability in pinboard updates in ThoughtSpot 4.4.1 through 5.1.1 (before 5.1.2) allows a low-privilege user with write access to at least one pinboard to corrupt pinboards of another user in the application by spoofing GUIDs in pinboard update requests, effectively deleting them.