PT-2024-33: Business logic vulnerability in Passwork
Vendor: Passwork
Vulnerable product: Passwork
Vulnerable version: 6.4.0
Vulnerability type:
• CWE-841: Improper Enforcement of Behavioral Workflow
Identifier (ID):
• BDU:2024-08020
Vulnerability vector:
• Base vulnerability score (CVSSv3.1): CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
• Severity (CVSSv3.1): 6.5(medium)
• Base vulnerability score (CVSSv4.0): CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
• Severity (CVSSv4.0): 7.1(high)
Description:
The vulnerability was identified in Passwork version 6.4.0.
The application's logic requires the user to perform a correct sequence of actions to implement the functionality.
The vulnerability in the business logic can be exploited by an attacker to gain access to the application's functionality without correctly performing these steps.
Vulnerability status: Confirmed by vendor
Date of vulnerability remediation: 09.10.2024
Recommendations:
• Update to version 6.4.3 or higher
Additional information: Aleksey Pisarenko (Positive Technologies)