The “Bytebase” application does not restrict low privilege user to access “admin issues“ for which an unauthorized user can view the “OPEN” and “CLOSED” issues by “Admin” and the affected endpoint is “/issue”.
References
Link | Resource |
---|---|
https://github.com/bytebase/bytebase/blob/1.0.4/frontend/src/store/modules/issue.ts#L108-#L187 | Release Notes Third Party Advisory |
https://www.mend.io/vulnerability-database/CVE-2022-32169 | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-09-28 03:15
Updated : 2022-10-03 11:41
NVD link : CVE-2022-32169
Mitre link : CVE-2022-32169
JSON object : View
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
Products Affected
bytebase
- bytebase