Description
A flaw was found in the BPMN editor in version jBPM 7.51.0.Final. Any authenticated user from any project can see the name of Ruleflow Groups from other projects, despite the user not having access to those projects. The highest threat from this vulnerability is to confidentiality.
Related CPE's
Vulnerable
Vulnerable
References
https://bugzilla.redhat.com/show_bug.cgi?id=1946213
Issue TrackingVendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1946213
Issue TrackingVendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
4.3 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2021-06-01T12:15:08.560Z
4 years agoLast modified
2024-11-21T04:46:19.427Z
1 year ago