{"id":"GHSA-r6ph-5fp2-3w2v","summary":"Microcks's POST /api/import and POST /api/export endpoints allow non-administrator access","details":"In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access.","aliases":["CVE-2024-44076"],"modified":"2024-11-19T05:38:35.765330Z","published":"2024-08-19T03:30:48Z","database_specific":{"cwe_ids":["CWE-269","CWE-863"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-08-19T21:48:56Z","nvd_published_at":"2024-08-19T03:15:03Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-44076"},{"type":"WEB","url":"https://github.com/microcks/microcks/issues/1212"},{"type":"WEB","url":"https://github.com/microcks/microcks/commit/4bb98d76f050710e42f5978877fe70e2f6edabf0"},{"type":"WEB","url":"https://github.com/microcks/microcks/commit/a47d105eb45dac5a0712d6e6bf12b3a4347e5e68"},{"type":"PACKAGE","url":"https://github.com/microcks/microcks"},{"type":"WEB","url":"https://github.com/microcks/microcks/compare/1.9.1-fix-1...1.10.0"},{"type":"WEB","url":"https://github.com/microcks/microcks/releases/tag/1.10.0"}],"affected":[{"package":{"name":"io.github.microcks:microcks-app","ecosystem":"Maven","purl":"pkg:maven/io.github.microcks/microcks-app"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.10.0"}]}],"versions":["1.0.0","1.0.0-RC1","1.1.0","1.1.1","1.2.0","1.2.1","1.3.0","1.4.0","1.4.1","1.4.1-fix-1","1.4.1-fix-2","1.5.0","1.5.0-RC1","1.5.0-RC2","1.5.1","1.5.1-RC1","1.5.1-fix-1","1.5.2","1.5.2-RC1","1.6.0","1.6.0-RC1","1.6.0-fix-1","1.6.0-fix-2","1.6.1","1.7.0","1.7.0-RC1","1.7.1","1.7.1-fix-1","1.8.0","1.8.0-fix-1","1.8.1","1.8.1-M1","1.9.0","1.9.0-fix-1","1.9.0-fix-2","1.9.1","1.9.1-fix-1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/08/GHSA-r6ph-5fp2-3w2v/GHSA-r6ph-5fp2-3w2v.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}