The “Bytebase” application does not restrict low privilege user to access admin “projects“ for which an unauthorized user can view the “projects“ created by “Admin” and the affected endpoint is “/api/project?user=${userId}”.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Mend
Published: 2022-09-28T09:30:18.081795Z
Updated: 2024-09-16T17:03:20.651Z
Reserved: 2022-05-31T00:00:00
Link: CVE-2022-32170
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-09-28T10:15:09.740
Modified: 2024-11-21T07:05:52.460
Link: CVE-2022-32170
Redhat
No data.