The "Bytebase" application does not restrict low privilege user from accessing admin projects
The "Bytebase" application does not restrict low privilege user from accessing admin projects for which an unauthorized user can view the "projects" created by "Admin". The affected endpoint is /api/project?user=${userId}
.
admin@example.com:admin
) and Developer "User" (user@admin.com:user
) and then click on "Projects".{ "severity": "MODERATE", "cwe_ids": [ "CWE-285" ], "nvd_published_at": "2022-09-28T10:15:00Z", "github_reviewed": true, "github_reviewed_at": "2024-04-24T20:10:21Z" }