Home
HIGH: 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H >= 9.2.0, < 9.2.2
affected
Description
Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerability that allows authenticated users to access unauthorized content. Upgrade Kiteworks Core to version 9.2.2 or later to receive a patch.
Problem types
CWE-282: Improper Ownership Management
Product status
References
github.com/...sories/security/advisories/GHSA-5gqr-cpr6-wvm5