VDB
KO
HIGH 8.1

PYSEC-2024-296

Details

OpenCTI is an open source platform allowing organizations to manage their cyber threat intelligence knowledge and observables. Due to lack of certain security controls on the profile edit functionality, an authenticated attacker with low privileges can gain administrative privileges on the web application.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / pycti
Introduced in: 0 Fixed in: 5.12.32
Fix pip install --upgrade 'pycti>=5.12.32'

References