OpenCTI is an open source platform allowing organizations to manage their cyber threat intelligence knowledge and observables. Due to lack of certain security controls on the profile edit functionality, an authenticated attacker with low privileges can gain administrative privileges on the web application.
References
Link | Resource |
---|---|
https://github.com/OpenCTI-Platform/opencti/security/advisories/GHSA-qx4j-f4f2-vjw9 | Vendor Advisory |
https://github.com/OpenCTI-Platform/opencti/security/advisories/GHSA-qx4j-f4f2-vjw9 | Vendor Advisory |
Configurations
History
22 May 2025, 18:07
Type | Values Removed | Values Added |
---|---|---|
First Time |
Citeum opencti
Citeum |
|
CWE | NVD-CWE-noinfo | |
References | () https://github.com/OpenCTI-Platform/opencti/security/advisories/GHSA-qx4j-f4f2-vjw9 - Vendor Advisory | |
CPE | cpe:2.3:a:citeum:opencti:*:*:*:*:*:*:*:* |
21 Nov 2024, 09:02
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/OpenCTI-Platform/opencti/security/advisories/GHSA-qx4j-f4f2-vjw9 - |
24 May 2024, 01:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
23 May 2024, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-23 12:15
Updated : 2025-05-22 18:07
NVD link : CVE-2024-26139
Mitre link : CVE-2024-26139
CVE.ORG link : CVE-2024-26139
JSON object : View
Products Affected
citeum
- opencti
CWE