An attacker can bypass the automation-eda-controller restrictions, via Websocket Activation_id Spoofing, in order to obtain the privileges of a user. See online: https://vigilance.fr/vulnerability/...
This story is only covered by news sources that have yet to be evaluated by the independent media monitoring agencies we use to assess the quality and reliability of news outlets on our platform. Learn more here.
An attacker can bypass the automation-eda-controller restrictions, via Websocket Activation_id Spoofing, in order to obtain the privileges of a user. See online: https://vigilance.fr/vulnerability/...