Pitchfork version 1.4.6 RC1 contains an Improper Privilege Management vulnerability...
Vulnerability Description
Pitchfork version 1.4.6 RC1 contains an Improper Privilege Management vulnerability in Trident Pitchfork components that can result in A standard unprivileged user could gain system administrator permissions within the web portal.. This attack appear to be exploitable via The user must be able to login, and could edit their profile and set the "System Administrator" permission to "yes" on themselves.. This vulnerability appears to have been fixed in 1.4.6 RC2.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-1000133
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/tridentli/trident/releases/tag/DEV_1.4.6-RC2
- https://github.com/tridentli/pitchfork/issues/168
- https://github.com/tridentli/pitchfork/commit/9fd07cbe4f93e1367e142016e9a205366680dd54
- https://thomas-ward.net/security-advisories/trident-trusted-communications-platform-privilege-escalation-issue-advisory/
- https://github.com/tridentli/pitchfork/commit/33549f15707801099e1253dd5e79369bd48eb59b
Affected Vendor
secluded
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.