•  
      request #44068 Special and always there fields permissions are not verified
    Infos
    #44068
    Thomas Gerbet (tgerbet)
    2025-08-19 14:58
    2025-07-29 17:26
    45766
    Details
    Special and always there fields permissions are not verified

    Impact

    An attacker can access to the content of the special and always there fields of accessible artifacts even if the permissions associated with the underlying fields do not allow it.

    CVSSv3.1 score: 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

    References

    CWE 863
    CVE-2025-54877

    Cross tracker search
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Empty
    Closed
    2025-08-01
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2025-08-06 11:40

    CVE-2025-54877 has been assigned to this issue.


    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes