Skip to content

Attachments can be created and edited by user with read-only permissions

Moderate
SchrodingersGat published GHSA-525m-qp9h-6p52 Jun 18, 2022

Package

No package listed

Affected versions

< 0.8.0

Patched versions

0.8.0

Description

Impact

Attachments (files and links) can be created and edited by users without the required permissions being granted.

The various relevant API endpoints did not have the correct permission sets applied, which allows any authenticated user to upload and modify attachments, even if that user does not nominally have the required permissions.

Patches

  • Refer to PR #3218
  • This patch will be applied to the upcoming 0.8.0 stable release

Workarounds

None

References

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

No known CVE

Weaknesses

Credits