ZeroHour

CVE-2024-3317

CVSS 3.1
6.5 medium
EPSS
<1%p37
Published
()
Modified
Description

An improper access control was identified in the Identity Security Cloud (ISC) message server API that allowed an authenticated user to exfiltrate job processing metadata (opaque messageIDs, work queue depth and counts) for other tenants.

Weakness
CWE-1284
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.