Improper authorization control for web services In pycti
Description
OpenCTI: Privilege escalation via graphQL API is abusable by organization admins, due to incorrect ACL on userEdit relationAdd
Summary
An organization admin can escalate their privileges by adding a user from a different organization with higher privileges, to their own organization.
Impact
Full platform access, access to sensitive or proprietary information.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
pypi | 6.9.7 |
Aliases
1. 2. 3. 4. 5.
References
1. 2.