CyberRota Analysis
AI-GeneratedAn authenticated attacker can exploit a vulnerability in the system by manipulating the "Grpc-Metadata-USER" header to impersonate another GUI user, potentially escalating their privileges from a low-level account to that of an administrator. This critical vulnerability poses a significant risk of account takeover, making it essential for organizations using affected products to prioritize immediate remediation efforts to protect against unauthorized access. Security teams should focus on implementing proper input validation and access controls to mitigate this threat.
Original NVD Description
An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator.