Vulnerabilities > CVE-2023-50267 - Authorization Bypass Through User-Controlled Key vulnerability in Metersphere

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
metersphere
CWE-639

Summary

MeterSphere is a one-stop open source continuous testing platform. Prior to 2.10.10-lts, the authenticated attackers can update resources which don't belong to him if the resource ID is known. This issue if fixed in 2.10.10-lts. There are no known workarounds.

Vulnerable Configurations

Part Description Count
Application
Metersphere
49