Keyfactor Command before 12.5.0 has Incorrect Access...
High severity
Unreviewed
Published
Dec 18, 2024
to the GitHub Advisory Database
•
Updated Dec 21, 2024
Description
Published by the National Vulnerability Database
Dec 18, 2024
Published to the GitHub Advisory Database
Dec 18, 2024
Last updated
Dec 21, 2024
Keyfactor Command before 12.5.0 has Incorrect Access Control: access tokens are over permissioned, aka 64099. The fixed versions are 11.5.1.1, 11.5.2.1, 11.5.3.1, 11.5.4.5, 11.5.6.1, 11.6.0, 12.2.0.1, 12.3.0.1, 12.4.0.1, 12.5.0, and 24.4.0.
References