Summary
Any user with the capability manage customizations can edit webhook that will execute javascript code.
This can be abused to cause a denial of service attack by prototype pollution, making the node js server running the OpenCTI frontend become unavailable.
This is a complementary security fix of GHSA-mf88-g2wq-p7qm
Summary
Any user with the capability manage customizations can edit webhook that will execute javascript code.
This can be abused to cause a denial of service attack by prototype pollution, making the node js server running the OpenCTI frontend become unavailable.
This is a complementary security fix of GHSA-mf88-g2wq-p7qm