CVE-2024-29866
CRITICALDatalust Seq <2023.4.11151, <2024.1.11146 - Privilege Escalation
Title source: llmDescription
Datalust Seq before 2023.4.11151 and 2024 before 2024.1.11146 has Incorrect Access Control because a Project Owner or Organization Owner can escalate to System privileges.
References (2)
Core 2
Core References
Product
https://datalust.co
Issue Tracking
https://github.com/datalust/seq-tickets/issues/2127
Scores
CVSS v3
9.1
EPSS
0.0069
EPSS Percentile
48.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-284
Status
published
Products (1)
datalust/seq
< 2023.4.11151
Published
Mar 21, 2024
Tracked Since
Feb 18, 2026