MEDIUM
A Broken Access Control vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, and 5.4.0 before 5.4.10 allows remote, authenticated, and unprivileged users to retrieve alerts, cases, logs, observables, or tasks, regardless of the user's permissions, through a specific API endpoint
Published May 23, 2025
6.8
MEDIUMCVSS 4.0
EPSS 0.32%
Description
Affected products
Remediation
References (2)
Change history (0)
No recorded changes yet.