CVE-2020-11465
Summary
| CVE | CVE-2020-11465 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-01 21:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | An issue was discovered in Deskpro before 2019.8.0. The /api/apps/* endpoints failed to properly validate a user's privilege, allowing an attacker to control/install helpdesk applications and leak current applications' configurations, including applications used as user sources (used for authentication). This enables an attacker to forge valid authentication models that resembles any user on the system. |
Risk And Classification
Problem Types: CWE-862
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Deskpro Security Update (2019-09) - News - Deskpro Support | MISC | support.deskpro.com | Release Notes, Vendor Advisory |
| Attacking HelpDesks Part 1: RCE Chain on DeskPro, with Bitdefender as a Case Study – Redforce | MISC | blog.redforce.io | Exploit, Third Party Advisory |
| Deskpro v2019.8.0 Released (Security Update) - Release Announcements - Deskpro Support | MISC | support.deskpro.com | Release Notes, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.