Impact
There is a priviledge escalation vulnerability affecting OpenCTI that can be exploited by unauthenticated attackers, and enables to query the API as any existing user including the admin set by default.
Patches
This issue has been fixed since version 6.9.13.
Workarounds
There is no workaround for the priviledge escalation issue. One recommended remediation is to disable the default admin using APP__ADMIN__EXTERNALLY_MANAGED configuration.
Impact
There is a priviledge escalation vulnerability affecting OpenCTI that can be exploited by unauthenticated attackers, and enables to query the API as any existing user including the admin set by default.
Patches
This issue has been fixed since version 6.9.13.
Workarounds
There is no workaround for the priviledge escalation issue. One recommended remediation is to disable the default admin using APP__ADMIN__EXTERNALLY_MANAGED configuration.