In the Bentley ALIM Web application, certain...
Critical severity
Unreviewed
Published
Feb 26, 2024
to the GitHub Advisory Database
•
Updated Aug 14, 2024
Description
Published by the National Vulnerability Database
Feb 26, 2024
Published to the GitHub Advisory Database
Feb 26, 2024
Last updated
Aug 14, 2024
In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts to download files. This is fixed in Assetwise ALIM Web 23.00.02.03 and Assetwise Information Integrity Server 23.00.04.04.
References