[MAVEN:GHSA-XG89-VVWP-9C27] Exposure of Sensitive Information in OpenGoofy Hippo4j

Severity Moderate
Affected Packages 1
CVEs 1

Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker toescalate privileges via the AddUser method of the UserController function in Tenant Management module.

Package Affected Version
pkg:maven/cn.hippo4j/hippo4j-core <= 1.4.3
ID
MAVEN:GHSA-XG89-VVWP-9C27
Severity
moderate
URL
https://github.com/advisories/GHSA-xg89-vvwp-9c27
Published
2023-03-16T03:30:16
(18 months ago)
Modified
2023-03-30T05:09:21
(17 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/cn.hippo4j/hippo4j-core cn.hippo4j hippo4j-core <= 1.4.3
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...