GHSA-j52c-cvfp-wrxgMediumCVSS 8.5
A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made...
🔗 CVE IDs covered (1)
📋 Description
A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible. This vulnerability requires a minimum role of Enterprise Standard Admin.
This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.