Support Core Plugin defines the permission Support/DownloadBundle that allows users without Overall/Administer permission to create and download support bundles containing a limited set of diagnostic information.
Support Core Plugin 1206.v14049fabd860 and earlier does not correctly perform permission checks in several HTTP endpoints.
This allows attackers with Support/DownloadBundle permission to download a previously created support bundle containing information limited to users with Overall/Administer permission.
Support Core Plugin 1206.1208.v9b7a1d48db_0f deprecates the Support/DownloadBundle permission. The Overall/Administer permission is now required to download support bundles.
{
"github_reviewed": true,
"severity": "MODERATE",
"nvd_published_at": "2022-11-15T20:15:00Z",
"cwe_ids": [
"CWE-276",
"CWE-863"
],
"github_reviewed_at": "2022-11-21T22:21:38Z"
}