You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
It has been observed that Cortex Version: 3.1.1-1 application is vulnerable to Authentication Bypass. An attacker with an account in the application is able to log into the account of any other application user (including the administrator) which in consequence may lead to a compromise of the application and each of its users.
Steps to Reproduce
Prepare a POST request to /api/login with EMPTY password of existing user
Request Type
Bug
Work Environment
Problem Description
It has been observed that Cortex Version: 3.1.1-1 application is vulnerable to Authentication Bypass. An attacker with an account in the application is able to log into the account of any other application user (including the administrator) which in consequence may lead to a compromise of the application and each of its users.
Steps to Reproduce
Possible Solutions
It is the same issue as on thehive 2391
Complementary information
tested on cortex integrated with AD
The text was updated successfully, but these errors were encountered: