PYSEC-2025-178

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/pycti/PYSEC-2025-178.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2025-178
Aliases
Published
2025-04-30T19:15:55.070Z
Modified
2026-05-20T09:19:14.163895Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
[none]
Details

OpenCTI is an open-source cyber threat intelligence platform. In versions starting from 6.4.8 to before 6.4.10, the allow/deny lists can be bypassed, allowing a user to change attributes that are intended to be unmodifiable by the user. It is possible to toggle the external flag on/off and change the own token value for a user. It is also possible to edit attributes that are not in the allow list, such as otp_qr and otp_activated. If external users exist in the OpenCTI setup and the information about these users identities is sensitive, the above vulnerabilities can be used to enumerate existing user accounts as a standard low privileged user. This issue has been patched in version 6.4.10.

References

Affected packages

PyPI / pycti

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.4.9
Fixed
6.4.11

Affected versions

6.*
6.4.9
6.4.10

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/pycti/PYSEC-2025-178.yaml"