CVE-2020-9300
The Access Control issues include allowing a regular user to view a restricted incident, user role escalation to admin, users adding themselves as a participant in a restricted incident, and users able to view restricted incidents via the search feature.
Does this matter?
Lower severity and a low EPSS score (0.94%). Track it; it rarely justifies an emergency change on its own.
Description
The Access Control issues include allowing a regular user to view a restricted incident, user role escalation to admin, users adding themselves as a participant in a restricted incident, and users able to view restricted incidents via the search feature. If your install has followed the secure deployment guidelines the risk of this is lowered, as this may only be exploited by an authenticated user.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.94% probability · 59th percentile
- CISA KEV
- Not listed
- Affected
- netflix/dispatch
- Source
- security-report@netflix.com
References
- https://github.com/Netflix/dispatch/releases/tag/v20201106Third Party Advisory
- https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2020-005.mdThird Party Advisory
- https://github.com/Netflix/dispatch/releases/tag/v20201106Third Party Advisory
- https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2020-005.mdThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.