SB20240530175 - Improper access control in MeterSphere
Published: May 30, 2024 Updated: April 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper access control (CVE-ID: CVE-2024-36118)
The vulnerability allows a remote user to view unauthorized workspace test cases.
The vulnerability exists due to improper access control in the workspace functional test case view when handling direct URL access to test case pages. A remote privileged user can use a copied test case URL to view unauthorized workspace test cases.
User interaction is required to obtain and open the copied URL.
Remediation
Install update from vendor's website.