VDB
KO
MEDIUM 4.3

PYSEC-2024-298

Details

OpenCTI is an open-source cyber threat intelligence platform. Before 6.3.0, general users can access information that can only be accessed by users with access privileges to admin and support information (SETTINGS_SUPPORT). This is due to inadequate access control for support information (http://<opencti_domain>/storage/get/support/UUID/UUID.zip), and that the UUID is available to general users using an attached query (logs query). This vulnerability is fixed in 6.3.0.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / pycti
Introduced in: 0 Fixed in: 6.3.0
Fix pip install --upgrade 'pycti>=6.3.0'

References