Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Idira Secrets Manager Self-Hosted: Improper Access Control in Internal Cluster Endpoints
Vulnerability Description
Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve unauthorized secrets or cause a denial of service (DoS). CyberArk Security Bulletin: CA26-20
CVSS Information
N/A
Vulnerability Type
访问控制不恰当
Vulnerability Title
CyberArk Idira Secrets Manager Self-Hosted 访问控制错误漏洞
Vulnerability Description
CyberArk Idira Secrets Manager Self-Hosted是美国CyberArk公司的一个企业级机密信息管理平台。 CyberArk Idira Secrets Manager Self-Hosted 13.8.0及之前版本存在访问控制错误漏洞,该漏洞源于内部集群端点中访问控制不当,可能导致拥有标准节点级凭据的远程经过身份验证的攻击者利用这些端点检索未经授权的机密或造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A