A race condition exists in Audited 4.0.0 to 5.3.3 that can result in an authenticated user to cause audit log entries to be attributed to another user.
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Link | Tags |
---|---|
https://github.com/collectiveidea/audited/security/advisories/GHSA-hjp3-5g2q-7jww | vendor advisory |
https://github.com/collectiveidea/audited/issues/601 | patch vendor advisory issue tracking |
https://github.com/collectiveidea/audited/pull/669 | patch related |
https://github.com/collectiveidea/audited/pull/671 | patch related |
https://github.com/advisories/GHSA-hjp3-5g2q-7jww | third party advisory |
https://vulncheck.com/advisories/vc-advisory-GHSA-hjp3-5g2q-7jww | third party advisory |