CRITICAL
C4G BLIS Improper Access Control
Published Nov 6, 2019
10.0
CRITICALCVSS 3.1
EPSS 1.32%
Description
Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.4 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may change the password of any administrator-level user.
Affected products
-
Affected
- ≥ unspecified, ≤ 3.4
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Computing For Good | Basic Laboratory Information System | unknown | Affected
|
- ≤ 3.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
C4G BLIS users should update to version 3.5 or later.
Weaknesses (2)
References (2)
- https://blog.rapid7.com/2019/09/10/r7-2019-09-cve-2019-5617-cve-2019-5643-cve-2019-5644-c4g-blis-authentication-and-authorization-vulnerabilities-fixed/ x_refsource_MISCExploitThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-15192 Advisory
| Link | Providers | Tags |
|---|---|---|
| https://blog.rapid7.com/2019/09/10/r7-2019-09-cve-2019-5617-cve-2019-5643-cve-2019-5644-c4g-blis-authentication-and-authorization-vulnerabilities-fixed/ | x_refsource_MISCExploitThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-15192 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner rapid7
Published Nov 6, 2019
Updated Sep 17, 2024
Reserved Jan 7, 2019
Link CVE-2019-5617
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data