The “Bytebase” application does not restrict low privilege user to access admin “projects“ for which an unauthorized user can view the “projects“ created by “Admin” and the affected endpoint is “/api/project?user=${userId}”.
References
Link | Resource |
---|---|
https://github.com/bytebase/bytebase/blob/1.0.4/frontend/src/store/modules/project.ts#L166-#L197 | Release Notes Third Party Advisory |
https://www.mend.io/vulnerability-database/CVE-2022-32170 | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-09-28 03:15
Updated : 2022-10-03 11:41
NVD link : CVE-2022-32170
Mitre link : CVE-2022-32170
JSON object : View
CWE
CWE-285
Improper Authorization
Products Affected
bytebase
- bytebase