Description
The “Bytebase” application does not restrict low privilege user to access admin “projects“ for which an unauthorized user can view the “projects“ created by “Admin” and the affected endpoint is “/api/project?user=${userId}”.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6762 | Bytebase allows low-privilege users to view admin projects |
Github GHSA |
GHSA-9mmc-27gw-w6mq | Bytebase allows low-privilege users to view admin projects |
References
History
Wed, 21 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mend
Published:
Updated: 2025-05-21T14:05:26.762Z
Reserved: 2022-05-31T00:00:00.000Z
Link: CVE-2022-32170
Updated: 2024-08-03T07:32:56.023Z
Status : Modified
Published: 2022-09-28T10:15:09.740
Modified: 2025-05-21T14:15:24.923
Link: CVE-2022-32170
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA