High7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

PT-2024-33: Business logic vulnerability in Passwork

PT-2024-33: Business logic vulnerability in Passwork

Vendor: Passwork

Vulnerable product: Passwork

Vulnerable version: 6.4.0

Vulnerability type:

CWE-841: Improper Enforcement of Behavioral Workflow

Identifier (ID):

BDU:2024-08020

Vulnerability vector:

Base vulnerability score (CVSSv3.1): CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Severity (CVSSv3.1): 6.5(medium)

Base vulnerability score (CVSSv4.0): CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Severity (CVSSv4.0): 7.1(high)

Description:

The vulnerability was identified in Passwork version 6.4.0.

The application's logic requires the user to perform a correct sequence of actions to implement the functionality.

The vulnerability in the business logic can be exploited by an attacker to gain access to the application's functionality without correctly performing these steps.

Vulnerability status: Confirmed by vendor

Date of vulnerability remediation: 09.10.2024

Recommendations:

Update to version 6.4.3 or higher

Additional information: Aleksey Pisarenko (Positive Technologies)