Security Insight: Read our blog post on the evolution of Password Storage in MIDAS

MIDAS Security Advisory

19th May 2021

Summary

A vulnerability was discovered and responsibly disclosed to our security team by an independent security researcher.

The vulnerability could allow a MIDAS user with limited permissions to indirectly elevate the permissions assigned to their user account.

Our security team are not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.


Common Vulnerability Scoring System Assessment

4.8
(Medium)
Our security team have internally assessed this vulnerability against the Common Vulnerability Scoring System (CVSS v3.1).

It has been classified with a score of 4.8 (Medium).

Vector String: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N/E:P/RL:O/RC:C/IR:L/MAV:N/MAC:L/MPR:L/MUI:R/MS:U/MC:N/MI:L/MA:N


Affected Products

Vulnerable Products

Products Confirmed Not Vulnerable


What You Should Do


Workarounds

There are no known workarounds that address this vulnerability.

Timeline


Acknowledgements

Times shown are UTC unless otherwise stated