EIQ-2020-0001
ID |
EIQ-2020-0001 |
CVE |
- |
Description |
A signed-in user can view saved graph thumbnails |
Date |
09 Jan 2020 |
Severity |
1 - LOW |
CVSSv3 score |
CVSSv3 score not available on NIST NVD. |
Status |
2.7.0 |
Assessment |
A signed-in platform user without admin access rights can view the thumbnail of a graph saved to an unlisted workspace, regardless of the user being a collaborator of the unlisted workspace or not. To do so, a signed-in platform user must have the ID of the graph whose thumbnail they want to access. Example: https://${platform_host_name}/main/intel/workspaces/3?graph-editor=13 To access a thumbnail by graph ID:
The .png image size and the low thumbnail image resolution do not enable leveraging graph content acquired in this way. We plan to enforce user access check for saved graphs at private API level from release 2.7.0. |
Mitigation |
Upgrade to EclecticIQ Platform 2.7.0 or later. |
Affected versions |
2.6.0 and earlier. |
Notes |
- |
< Back to all security issues and mitigation actions
In release notes 2.7.0