SB20240530175 - Improper access control in MeterSphere



SB20240530175 - Improper access control in MeterSphere

Published: May 30, 2024 Updated: April 24, 2026

Security Bulletin ID SB20240530175
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper access control (CVE-ID: CVE-2024-36118)

The vulnerability allows a remote user to view unauthorized workspace test cases.

The vulnerability exists due to improper access control in the workspace functional test case view when handling direct URL access to test case pages. A remote privileged user can use a copied test case URL to view unauthorized workspace test cases.

User interaction is required to obtain and open the copied URL.


Remediation

Install update from vendor's website.