There is an improper access control vulnerability in...
High severity
Unreviewed
Published
Aug 17, 2022
to the GitHub Advisory Database
•
Updated Jul 5, 2023
Description
Published by the National Vulnerability Database
Aug 16, 2022
Published to the GitHub Advisory Database
Aug 17, 2022
Last updated
Jul 5, 2023
There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a remote, unauthenticated attacker to access an API that may induce Esri Portal for ArcGIS to read arbitrary URLs.
References