Vulnerabilities > CVE-2018-20226 - Unspecified vulnerability in Thehive-Project Cortex
Attack vector
NETWORK Attack complexity
LOW Privileges required
HIGH Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
An organization administrator can add a super administrator in THEHIVE PROJECT Cortex before 2.1.3 due to the lack of overriding the Role.toString method.
Vulnerable Configurations
References
- https://github.com/TheHive-Project/Cortex/blob/2.1.3/CHANGELOG.md
- https://github.com/TheHive-Project/Cortex/blob/2.1.3/CHANGELOG.md
- https://github.com/TheHive-Project/Cortex/commit/1aaf2182a6b722ad539e2717bc11967d1bde723a
- https://github.com/TheHive-Project/Cortex/commit/1aaf2182a6b722ad539e2717bc11967d1bde723a
- https://github.com/TheHive-Project/Cortex/issues/158
- https://github.com/TheHive-Project/Cortex/issues/158