CVE-2023-49112
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/06/2024
Last modified:
04/11/2025
Description
Kiuwan provides an API endpoint<br />
<br />
/saas/rest/v1/info/application<br />
<br />
to get information about any <br />
application, providing only its name via the "application" parameter. This endpoint lacks proper access <br />
control mechanisms, allowing other authenticated users to read <br />
information about applications, even though they have not been granted <br />
the necessary rights to do so.<br />
<br />
<br />
<br />
This issue affects Kiuwan SAST:
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM



