RULE(RULE ID:338330)

Rule General Information
Release Date: 2024-08-21
Rule Name: Weaver Ecology10 appThirdLogin Authentication Bypass Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Weaver Ecology10 is a product dedicated to providing comprehensive collaborative management software solutions for enterprises. Through a comprehensive upgrade of its underlying architecture, it achieves high availability, high concurrency, and high-performance technical capabilities. This product adopts a microservice architecture that supports front-end componentization and the splitting and merging of back-end services. It also provides a database multi tenant design, read-write separation, and automated monitoring operation and maintenance platform, ensuring an efficient and smooth system experience and stability. There is an authentication bypass vulnerability in the appThirdLogin interface of Weaver Ecology 10, which allows unauthorized attackers to gain access to the admin privileges.
Impact: An unauthorized remote attacker can bypass authentication and gain access to the application with specially crafted requests.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.