Sourcegraph is a code search and navigation engine. Sourcegraph before version 3.30.0 has two potential information leaks. The site-admin area can be accessed by regular users and all information and features are properly protected except for daily usage statistics and code intelligence uploads and indexes. It is not possible to alter the information, nor interact with any other features in the site-admin area. The issue is patched in version 3.30.0, where the information cannot be accessed by unprivileged users. There are no workarounds aside from upgrading.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2021-08-02T22:00:12
Updated: 2024-08-03T23:33:55.836Z
Reserved: 2021-05-12T00:00:00
Link: CVE-2021-32787
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-08-02T22:15:08.223
Modified: 2024-11-21T06:07:44.377
Link: CVE-2021-32787
Redhat
No data.