Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerability that allows authenticated users to access unauthorized content. Upgrade Kiteworks Core to version 9.2.2 or later to receive a patch.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Accellion Kiteworks
cpe:2.3:a:accellion:kiteworks:9.2.0:*:*:*:*:*:*:*
|
— | — |
|
Accellion Kiteworks
cpe:2.3:a:accellion:kiteworks:9.2.1:*:*:*:*:*:*:*
|
— | — |