An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write access to escalate their privileges to the administrator's privileges. This affects app/controllers/UserCtrl.scala.
{
"unresolved_ranges": [
{
"vendor_product": "strangebee:thehive",
"extracted_events": [
{
"fixed": "2.13.4"
}
],
"source": "CPE_RANGE",
"cpes": [
"cpe:2.3:a:strangebee:thehive:*:*:*:*:*:*:*:*"
]
}
]
}