CyberRota Analysis
AI-GeneratedGoogle SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform are susceptible to improper privilege management, enabling authenticated attackers to escalate their privileges to system-level administrative access via a manipulated internal authentication header. Organizations utilizing affected versions should prioritize updating to the patched version to mitigate the risk of unauthorized access and potential exploitation. Immediate action is recommended for all users of the affected software to ensure security compliance.
Original NVD Description
Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative access using a crafted internal authentication header. This vulnerability was patched with version 6.3.85, and no customer action is needed.