T
he “Bytebase” application does not restrict low privilege user to access “admin issues“ for which an unauthorized user can view the “OPEN” and “CLOSED” issues by “Admin” and the affected endpoint is “/issue”.
References
| Link | Resource |
|---|---|
| https://github.com/bytebase/bytebase/blob/1.0.4/frontend/src/store/modules/issue.ts#L108-L187 | |
| https://www.mend.io/vulnerability-database/CVE-2022-32169 | Exploit Third Party Advisory |
| https://github.com/bytebase/bytebase/blob/1.0.4/frontend/src/store/modules/issue.ts#L108-L187 | |
| https://www.mend.io/vulnerability-database/CVE-2022-32169 | Exploit Third Party Advisory |
Configurations
History
21 May 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
21 Nov 2024, 07:05
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/bytebase/bytebase/blob/1.0.4/frontend/src/store/modules/issue.ts#L108-L187 - | |
| References | () https://www.mend.io/vulnerability-database/CVE-2022-32169 - Exploit, Third Party Advisory |
Information
Published : 2022-09-28 10:15
Updated : 2025-05-21 14:15
NVD link : CVE-2022-32169
Mitre link : CVE-2022-32169
CVE.ORG link : CVE-2022-32169
JSON object : View