LoxiLB v.0.9.7 and before is vulnerable to Incorrect Access Control which allows attackers to obtain sensitive information and escalate privileges.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://github.com/loxilb-io/loxilb | product |
https://gist.github.com/HouqiyuA/8c734c849c1a9b69ac96c46eba4acbcb | third party advisory |