In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade io.openremote:openremote-manager to version 1.24.1 or higher.
Affected versions of this package are vulnerable to Missing Authorization via the assetPredictedDatapointService.updateValues process. An attacker can modify predicted datapoints for assets by sending write requests to the predicted datapoint endpoint using only read-level privileges.