ZeroHour

CVE-2022-32170

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p46
Published
()
Modified
Description

The “Bytebase” application does not restrict low privilege user to access admin “projects“ for which an unauthorized user can view the “projects“ created by “Admin” and the affected endpoint is “/api/project?user=${userId}”.

Vendors
bytebase
Products
bytebase
Weakness
CWE-285
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.