-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| OPCFoundation.NetStandard.Opc.Ua.Server | nuget | < 1.4.370.9 | 1.4.370.9 |
The vulnerability stemmed from missing authorization checks in diagnostic data handling functions. The patch added: 1) Context parameter to propagation authorization context 2) FilterOutUnAuthorized() calls 3) Role permission validation via OnReadUserRolePermissions. The original versions of these Update*Diagnostics methods processed and exposed sensitive session/subscription information without verifying if the requester had SecurityAdmin role or owned the session, violating CWE-200. The commit 313aa2a explicitly added these security checks to prevent unauthorized access.
Ongoing coverage of React2Shell