Bytebase does not restrict low privilege user to access admin issues
Moderate severity
GitHub Reviewed
Published
Sep 29, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Package
Affected versions
>= 0.1.0, <= 1.0.4
Patched versions
None
Description
Published by the National Vulnerability Database
Sep 28, 2022
Published to the GitHub Advisory Database
Sep 29, 2022
Reviewed
Oct 4, 2022
Last updated
Jan 27, 2023
The
Bytebase
application does not restrict low privilege user to accessadmin issues
for which an unauthorized user can view theOPEN
andCLOSED
issues byAdmin
and the affected endpoint is/issue
.References