ntopng before 6.7.260717 Missing Authorization on the Notification Endpoint and Recipient Delete Handlers
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.1epss 0.2%
probabilidad de explotación
0.2%top 83% de las CVE
explotación observada
noninguna fuente lo reporta
ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured notification endpoints and recipients, silencing all alerts.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
Productos afectados
ntop · ntopngReferencias
https://github.com/ntop/ntopnghttps://github.com/ntop/ntopng/blob/f41cc1beff90e40e12bbc2cc135bdbf649ec559f/scripts/lua/rest/v2/delete/endpoints.luahttps://github.com/ntop/ntopng/blob/f41cc1beff90e40e12bbc2cc135bdbf649ec559f/scripts/lua/rest/v2/delete/recipients.luahttps://github.com/ntop/ntopng/commit/7d830f31af367745431c5d92e2e82fc432f6bdd8https://github.com/ntop/ntopng/security/advisories/GHSA-m22w-f647-vx88https://www.vulncheck.com/advisories/ntopng-before-6.7.260717-missing-authorization-on-the-notification-endpoint-and-recipient-delete-handlers