CyberRota Analysis
AI-GeneratedCoverity Connect versions from 2023.6.0 to 2026.3.0 are vulnerable to an authentication and authorization bypass due to a flaw in Spring Security, allowing unauthenticated attackers to exploit specific API endpoints. This vulnerability enables unauthorized access to sensitive data, posing a significant risk to organizations using these versions. Organizations utilizing Coverity Connect should prioritize patching this vulnerability to safeguard their data integrity and security.
Original NVD Description
A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malicious threat actor that can send a specially crafted HTTP request is able to bypass authentication and authorization controls on certain API endpoints to access data within Coverity.