CVE-2024-55471: Oqtane Idor Public Settings Exposure
A fallback `else` condition conditionally exposes data (such as 'Settings') by filtering properties via an `IsPrivate` check. This implementation can lead to an Insecure Direct Object Reference (IDOR) or unauthorized data disclosure if unprivileged users are allowed to hit this fallback logic by supplying arbitrary resource IDs. Access bounds should be stric
greprules fetch cve-2024-55471-oqtane-idor-public-settings-exposure --engine opengrepDescription
A fallback `else` condition conditionally exposes data (such as 'Settings') by filtering properties via an `IsPrivate` check. This implementation can lead to an Insecure Direct Object Reference (IDOR) or unauthorized data disclosure if unprivileged users are allowed to hit this fallback logic by supplying arbitrary resource IDs. Access bounds should be stric
Community feedback
0 signals from signed-in users.
- Useful
- 0
- False positive
- 0
- Metadata
- 0