CyberRota Analysis
AI-GeneratedIn multi-tenant deployments, the Publisher REST APIs lack proper tenant isolation, enabling a privileged user from one tenant to execute operations that can affect other tenants, including exposing or modifying API metadata. This critical vulnerability poses significant risks to data integrity and confidentiality across tenant environments. Organizations utilizing multi-tenant architectures should prioritize immediate remediation to safeguard against potential cross-tenant data breaches.
Original NVD Description
In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments.