CVE-2022-32170
EUVD-2022-676228.09.2022, 10:15
The “Bytebase” application does not restrict low privilege user to access admin “projects“ for which an unauthorized user can view the “projects“ created by “Admin” and the affected endpoint is “/api/project?user=${userId}”.EnginsightAffected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| bytebase | bytebase | 0.1.0 ≤ 𝑥 ≤ 1.0.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References