S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Feb 9, 2025

CVE-2024-50967 Scanner

CVE-2024-50967 Scanner - Improper Access Control vulnerability in DATAGERRY

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-50967
6.5
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability. An attacker can remotely access this endpoint without authentication, leading to unauthorized disclosure of sensitive information.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

DATAGERRY is a widely-used open-source software platform designed for configuration management, allowing IT administrators and DevOps teams to centralize and manage IT resources efficiently. It is utilized across various industries to manage complex IT environments by providing a user-friendly interface that simplifies operations. Organizations rely on DATAGERRY to automate workflows, ensuring seamless integration with other tools and systems. The software is adopted globally by enterprises seeking to improve operational efficiency and accuracy in managing resources. Its robust functionality and versatility make it a valuable asset for teams aiming to streamline configuration processes. Extensive community support ensures continuous improvements and adaptability of the platform.

The vulnerability identified in DATAGERRY involves improper access control, specifically within the /rest/rights/ REST API endpoint. This flaw allows attackers to remotely access sensitive information without authentication. Such vulnerabilities are critical as they expose crucial data to unauthorized individuals, potentially leading to further security breaches. Exploitation of this vulnerability can enable attackers to gain insights into the system's internal configurations and user permissions. Unauthorized access to sensitive data compromises the integrity and confidentiality of information within the platform. Addressing access control issues is vital to maintaining security and protecting organizational resources.

Technical details of this vulnerability include the ability to access the /rest/rights/ API endpoint using unauthenticated GET requests. The endpoint responds with sensitive information such as user rights and roles in JSON format. This response includes keys like "response_type," "model," and "time," indicating successful data retrieval without proper authorization checks. The flaw arises due to inadequate validation mechanisms, allowing unrestricted access to the endpoint. Proper implementation of access controls is necessary to secure API endpoints from unauthorized access. Without mitigation, this vulnerability could be exploited repeatedly, posing a continuous threat to system security.

If exploited, this vulnerability could lead to unauthorized disclosure of sensitive data, allowing attackers to gain insights into user permissions and potentially manipulate roles within the platform. Exposure of such information can facilitate further attacks, including privilege escalation or lateral movement within the network. Organizations may suffer reputational damage and loss of trust among clients and stakeholders. Financial repercussions may ensue due to potential data breaches and legal liabilities. Ensuring proper access controls are in place is essential to safeguarding sensitive information and preventing unauthorized system interactions.

Solution Advice
  • Implement proper access control measures to restrict unauthorized access to sensitive endpoints.
  • Review and update application permissions to ensure roles and rights are appropriately assigned.
  • Conduct regular security audits to identify and mitigate vulnerabilities related to access controls.
  • Consider using authentication mechanisms to enforce secure access to all API endpoints.
  • Stay informed about updates and patches provided by the software vendor to address security issues promptly.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.