Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-5rc4-v5mj-g8c4: Bytebase does not restrict low privilege user to access admin issues

The Bytebase application does not restrict low privilege user to access admin issues for which an unauthorized user can view the OPEN and CLOSED issues by Admin and the affected endpoint is /issue.

ghsa
#git#auth

Bytebase does not restrict low privilege user to access admin issues

Moderate severity GitHub Reviewed Published Sep 29, 2022 • Updated Oct 4, 2022

Related news

CVE-2022-32169: bytebase/issue.ts at 1.0.4 · bytebase/bytebase

The “Bytebase” application does not restrict low privilege user to access “admin issues“ for which an unauthorized user can view the “OPEN” and “CLOSED” issues by “Admin” and the affected endpoint is “/issue”.