{"id":"CVE-2025-24887","summary":"OpenCTI bypass of protected attribute update","details":"OpenCTI is an open-source cyber threat intelligence platform. In versions starting from 6.4.8 to before 6.4.10, the allow/deny lists can be bypassed, allowing a user to change attributes that are intended to be unmodifiable by the user. It is possible to toggle the `external` flag on/off and change the own token value for a user. It is also possible to edit attributes that are not in the allow list, such as `otp_qr` and `otp_activated`. If external users exist in the OpenCTI setup and the information about these users identities is sensitive, the above vulnerabilities can be used to enumerate existing user accounts as a standard low privileged user. This issue has been patched in version 6.4.10.","aliases":["GHSA-8262-pw2q-5qc3","PYSEC-2025-178"],"modified":"2026-08-12T03:51:49.100257025Z","published":"2025-04-30T18:27:24.530Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-284","CWE-657"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/24xxx/CVE-2025-24887.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/24xxx/CVE-2025-24887.json"},{"type":"ADVISORY","url":"https://github.com/OpenCTI-Platform/opencti/security/advisories/GHSA-8262-pw2q-5qc3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-24887"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/opencti-platform/opencti","events":[{"introduced":"7d5bb142deacc08e89aadcedfe2ebcb62427dcdf"},{"fixed":"38898481dc550a63d32e4e00a5a10d7b5f714e87"}],"database_specific":{"cpe":"cpe:2.3:a:citeum:opencti:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"6.4.8"},{"fixed":"6.4.10"},{"introduced":"0"},{"last_affected":"6.4.10"}],"source":["AFFECTED_FIELD","CPE_RANGE"]}}],"versions":["6.4.9","6.4.8"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-24887.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"}]}