CVE-2022-32169: bytebase - Improper Authorization
The “Bytebase” application does not restrict low privilege user to access “admin issues“ for which an unauthorized user can view the “OPEN” and “CLOSED” issues by “Admin” and the affected endpoint is “/issue”.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-32169?
CVE-2022-32169 is classified as a high severity vulnerability due to improper authorization allowing low privilege users to access admin issue details.
How do I fix CVE-2022-32169?
To fix CVE-2022-32169, ensure proper access controls are implemented on the '/issue' endpoint to restrict low privilege users from viewing admin issues.
What versions of Bytebase are affected by CVE-2022-32169?
CVE-2022-32169 affects Bytebase versions from 0.1.0 up to 1.0.4.
What type of vulnerability is CVE-2022-32169?
CVE-2022-32169 is an improper authorization vulnerability allowing unauthorized access to sensitive information.
Can CVE-2022-32169 lead to data exposure?
Yes, CVE-2022-32169 can lead to unauthorized users viewing sensitive data related to admin issues, which could impact data confidentiality.