CVE-2023-30946
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Jun 29, 2023
Updated: Nov 7, 2023
CWE ID 420
CWE ID 288
Summary
CVE-2023-30946 is a vulnerability affecting Foundry Issues. This issue arises when a user is added to an issue on a resource they don't have access to. Despite being unable to view the issue, they can still query Foundry's Notification API and obtain metadata, including the issue's RID, severity, the internal UUID of the author, and the user-defined title. This vulnerability poses a risk to the confidentiality of issue information.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share