Headline
GHSA-5rc4-v5mj-g8c4: Bytebase does not restrict low privilege user to access admin issues
The Bytebase
application does not restrict low privilege user to access admin issues
for which an unauthorized user can view the OPEN
and CLOSED
issues by Admin
and the affected endpoint is /issue
.
Bytebase does not restrict low privilege user to access admin issues
Moderate severity GitHub Reviewed Published Sep 29, 2022 • Updated Oct 4, 2022
Related news
CVE-2022-32169: bytebase/issue.ts at 1.0.4 · bytebase/bytebase
The “Bytebase” application does not restrict low privilege user to access “admin issues“ for which an unauthorized user can view the “OPEN” and “CLOSED” issues by “Admin” and the affected endpoint is “/issue”.