An incorrect permission assignment for critical resource...
High severity
Unreviewed
Published
Feb 2, 2024
to the GitHub Advisory Database
•
Updated Feb 2, 2024
Description
Published by the National Vulnerability Database
Feb 2, 2024
Published to the GitHub Advisory Database
Feb 2, 2024
Last updated
Feb 2, 2024
An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network.
We have already fixed the vulnerability in the following versions:
Qsync Central 4.4.0.15 ( 2024/01/04 ) and later
Qsync Central 4.3.0.11 ( 2024/01/11 ) and later
References