CVE-2023-49112

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/06/2024
Last modified:
04/11/2025

Description

Kiuwan provides an API endpoint<br /> <br /> /saas/rest/v1/info/application<br /> <br /> to get information about any <br /> application, providing only its name via the "application" parameter. This endpoint lacks proper access <br /> control mechanisms, allowing other authenticated users to read <br /> information about applications, even though they have not been granted <br /> the necessary rights to do so.<br /> <br /> <br /> <br /> This issue affects Kiuwan SAST: