An issue was discovered in Siren Investigate before 12.1.7. There is an ACL bypass on global objects.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://docs.support.siren.io/siren-platform-user-guide/12.1/release-notes.html | release notes vendor advisory |
https://docs.support.siren.io/siren-platform-user-guide/13.0/release-notes.html | release notes vendor advisory |