documentation.bonitasoft.com
https://documentation.bonitasoft.com/bonita/2024.1/release-notes CVE-2024-28087
MEDIUM
Bonitasoft Runtime Community edition's contains an insecure direct object references vulnerability
Record summary
CVE-2024-28087 has a selected CVSS score of 6.5 (medium).
Description
In Bonitasoft runtime Community edition, the lack of dynamic permissions causes IDOR vulnerability. Dynamic permissions existed only in Subscription edition and have now been restored in Community edition, where they are not custmizable.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 20, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
bonita_webBrowse bonitasoft / bonita_webDefault status: unknown | CVE List | Before 2024.2-u1 | affected |
org.bonitasoft.engine:bonita-serverBrowse Maven / org.bonitasoft.engine:bonita-server | GitHub Advisory | Before 10.1.0.W11 · Fixed in 10.1.0.W11 | affected |
References
5documentation.bonitasoft.com
https://documentation.bonitasoft.com/bonita/latest/release-notes github.com
https://github.com/bonitasoft/bonita-engine github.com
https://github.com/bonitasoft/bonita-engine/commit/1b3ac00f0178bfcfe8f01811a249b1893f0b1da1 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-28087