EIQ-2021-0013
| 
     ID  | 
                
     EIQ-2021-0013  | 
        
| 
     CVE  | 
                
     -  | 
        
| 
     Description  | 
                
     Users with only modify entities and read files permissions can access and export attachments from report entities they do not have access to.  | 
        
| 
     Date  | 
                
     17 August 2021  | 
        
| 
     Severity  | 
                
     2 - MEDIUM  | 
        
| 
     CVSSv3 score  | 
                
     CVSSv3 score not available on NIST NVD  | 
        
| 
     Status  | 
                
     
  | 
        
| 
     Assessment  | 
                
     An attacker with these permissions: 
 Can: 
 Expected: Users should not be able to access attachments from report entities that they are not authorized to access.  | 
        
| 
     Mitigation  | 
                
     Planned fix where platform enforces permissions correctly.  | 
        
| 
     Affected versions  | 
                
     2.10.x and earlier  | 
        
| 
     Notes  | 
                
     N/A  | 
        
< Back to all security issues and mitigation actions
In release notes 2.10.1