Description
Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker toescalate privileges via the AddUser method of the UserController function in Tenant Management module.
Remediation
References
https://github.com/opengoofy/hippo4j/issues/1061
Related Vulnerabilities
CVE-2019-19899 Vulnerability in maven package io.pebbletemplates:pebble
CVE-2021-21290 Vulnerability in maven package io.netty:netty-transport
CVE-2022-31197 Vulnerability in maven package org.postgresql:postgresql
CVE-2023-29509 Vulnerability in maven package org.xwiki.platform:xwiki-platform-flamingo-theme-ui