Vulnerabilities > Thoughtspot

DATE CVE VULNERABILITY TITLE RISK
2019-07-09 CVE-2019-12782 Authorization Bypass Through User-Controlled Key vulnerability in Thoughtspot 4.4.1/4.5.1/5.1.1
An authorization bypass vulnerability in pinboard updates in ThoughtSpot 4.4.1 through 5.1.1 (before 5.1.2) allows a low-privilege user with write access to at least one pinboard to corrupt pinboards of another user in the application by spoofing GUIDs in pinboard update requests, effectively deleting them.
network
low complexity
thoughtspot CWE-639
8.1