CVE-2024-3319
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
15/05/2024
Last modified:
15/05/2024
Description
An issue was identified in the Identity Security Cloud (ISC) Transform preview and IdentityProfile preview API endpoints that allowed an authenticated administrator to execute user-defined templates as part of attribute transforms which could allow remote code execution on the host.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL



