CRITICAL
Berkeley Open Infrastructure for Network Computing BOINC Server and Website Code version 0.9-1.0.2 contains a CWE-302: Authentication Bypass by Assumed-Immutable Data vulnerability in Website Terms of Service Acceptance Page that can result in Access to any user account
Published Dec 20, 2018
9.8
CRITICALCVSS 3.1
EPSS 1.88%
Description
Affected products
Remediation
References (2)
Change history (0)
No recorded changes yet.