An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users to register their own authentication plugins in Logpoint, resulting in unauthorized access.
CVSS
No CVSS.
References
Configurations
History
30 Apr 2025, 16:35
Type | Values Removed | Values Added |
---|---|---|
First Time |
Logpoint siem
Logpoint |
|
References | () https://docs.logpoint.com/docs/whats-new-in-logpoint/en/latest/ - Release Notes | |
References | () https://servicedesk.logpoint.com/hc/en-us/sections/7201103730845-Product-Security - Product | |
References | () https://servicedesk.logpoint.com/hc/en-us/articles/21968899128221-Authentication-Bypass-using-URL-endpoints-in-the-Authentication-Modules - Vendor Advisory | |
CPE | cpe:2.3:a:logpoint:siem:*:*:*:*:*:*:*:* |
07 Nov 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-07 17:15
Updated : 2025-04-30 16:35
NVD link : CVE-2024-48953
Mitre link : CVE-2024-48953
JSON object : View
Products Affected
logpoint
- siem
CWE
No CWE.