CVE-2024-3317
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/05/2024
Last modified:
15/05/2024
Description
An improper access control was identified in the Identity Security Cloud (ISC) message server API that allowed an authenticated user to exfiltrate job processing metadata (opaque messageIDs, work queue depth and counts) for other tenants.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM



