CVE-2024-14045: OpenBoxes Product Supplier Edit Controller RoleInterceptor.groovy improper authorization
A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Product Supplier Edit Controller. Executing a manipulation can lead to improper authorization. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. Upgrading to version 0.9.3 is able to resolve this issue. This patch is called f767ac1a5987d4865d9f158c6a967680f8e45468. It is suggested to upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenBoxesto a version that resolves this vulnerability.Fixed in 0.9.3Patch f767ac1a5987d4865d9f158c6a967680f8e45468
Event History
Frequently Asked Questions
Which deployments need to be remediated?
OpenBoxes versions up to and including 0.9.2 are affected. Upgrade to version 0.9.3, which includes patch f767ac1a5987d4865d9f158c6a967680f8e45468.
What does an attacker need to exploit this issue?
Exploitation can be performed remotely and requires low-level privileges; no user interaction is required. Public exploit information is available, increasing the likelihood of attempted exploitation.
Is a workaround available if upgrading is delayed?
The provided information identifies upgrading to 0.9.3 as the remediation. It does not provide a workaround or compensating configuration for systems that cannot be upgraded immediately.