Discover the security vulnerability in OpenAsset Digital Asset Management versions 12.0.19 and earlier. Learn how unauthenticated attackers can access sensitive project information and how to mitigate the risk.
OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier versions lack proper access controls, potentially exposing sensitive project information to unauthorized users.
Understanding CVE-2020-28861
This CVE identifies a security vulnerability in OpenAsset Digital Asset Management (DAM) versions 12.0.19 and earlier.
What is CVE-2020-28861?
The vulnerability in OpenAsset Digital Asset Management allows unauthenticated attackers to access sensitive project information by exploiting a lack of access controls on the /Stream/ProjectsCSV endpoint.
The Impact of CVE-2020-28861
The vulnerability could lead to unauthorized access to confidential project data stored within the application, posing a risk to data confidentiality and integrity.
Technical Details of CVE-2020-28861
OpenAsset Digital Asset Management's security flaw is detailed below:
Vulnerability Description
The issue arises from the failure to implement proper access controls on the /Stream/ProjectsCSV endpoint, enabling unauthorized users to retrieve potentially sensitive project details.
Affected Systems and Versions
Exploitation Mechanism
Unauthorized users can exploit the lack of access controls on the /Stream/ProjectsCSV endpoint to gain access to confidential project information without authentication.
Mitigation and Prevention
Protect your systems from CVE-2020-28861 with the following measures:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates