access control list bypass via link ID spoofing on unencrypted dynamic links
Summary
access control list bypass via link ID spoofing on unencrypted dynamic links. Red Hat rates this low (CVSS 4.8). Weakness: CWE-290.
What this means
In plain English
access control list bypass via link ID spoofing on unencrypted dynamic links. Red Hat rates this low (CVSS 4.8). Weakness: CWE-290. The flaw can allow operations or data access outside the authorization boundary intended by the affected product.
Recommended action
The parsed official advisory does not currently specify a fixed release, mitigation, or workaround. Review the linked vendor advisory for the latest guidance before making changes.
Rewritten locally from the scraped official advisory data above; no generative API is used. The vendor advisory is authoritative.
- 1.34
Official advisory · high-confidence parse· fetched 6 hours ago·verify at source
Fixed versions
No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.
Official advisory · high-confidence parse· fetched 6 hours ago·verify at source
Mitigation
The source record does not include mitigation steps. That is not a statement that no fix exists — read the vendor advisory below for the authoritative guidance.
Official advisory · high-confidence parse· fetched 6 hours ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.