{"id":"GHSA-hhcw-wwxv-g95c","summary":"Oqtane Framework Insecure Direct Object Reference vulnerability","details":"Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This allows unauthorized users to access sensitive information of other users by manipulating the id parameter.","aliases":["CVE-2024-55471"],"modified":"2024-12-20T19:59:35.706915Z","published":"2024-12-20T18:31:32Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-12-20T19:42:16Z","nvd_published_at":"2024-12-20T16:15:24Z","cwe_ids":["CWE-639"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-55471"},{"type":"WEB","url":"https://github.com/oqtane/oqtane.framework/pull/4880/files"},{"type":"PACKAGE","url":"https://github.com/oqtane/oqtane.framework"},{"type":"WEB","url":"https://medium.com/@Rudra_2158/cve-2024-55471-breaking-down-the-idor-vulnerability-in-oqtane-framework-c0f4b02f12fc"}],"affected":[{"package":{"name":"Oqtane.Framework","ecosystem":"NuGet","purl":"pkg:nuget/Oqtane.Framework"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.0.0"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","2.0.0","2.0.1","2.0.2","2.1.0","2.2.0","2.3.0","2.3.1","3.0.0","3.0.1","3.0.2","3.0.3","3.1.0","3.1.1","3.1.2","3.1.3","3.1.4","3.2.0","3.2.1","3.3.0","3.3.1","3.4.0","3.4.1","3.4.2","3.4.3","4.0.0","4.0.1","4.0.2","4.0.3","4.0.4","4.0.5","4.0.6","5.0.0","5.0.1","5.0.2","5.1.0","5.1.1","5.1.2","5.2.0","5.2.1","5.2.2","5.2.3","5.2.4","6.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-hhcw-wwxv-g95c/GHSA-hhcw-wwxv-g95c.json"}},{"package":{"name":"Oqtane.Server","ecosystem":"NuGet","purl":"pkg:nuget/Oqtane.Server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.0.0"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","2.0.0","2.0.1","2.0.2","2.1.0","2.2.0","2.3.0","2.3.1","3.0.0","3.0.1","3.0.2","3.0.3","3.1.0","3.1.1","3.1.2","3.1.3","3.1.4","3.2.0","3.2.1","3.3.0","3.3.1","3.4.0","3.4.1","3.4.2","3.4.3","4.0.0","4.0.1","4.0.2","4.0.3","4.0.4","4.0.5","4.0.6","5.0.0","5.0.1","5.0.2","5.1.0","5.1.1","5.1.2","5.2.0","5.2.1","5.2.2","5.2.3","5.2.4","6.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-hhcw-wwxv-g95c/GHSA-hhcw-wwxv-g95c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}