QID 995574
Date Published: 2023-10-17
QID 995574: Python (Pip) Security Update for vantage6 (GHSA-gc57-xhh5-m94r)
The endpoint /api/collaboration/{id}/task is used to collect all tasks from a certain collaboration. To get such tasks, a user should have permission to view the collaboration and to view the tasks in it. However, currently it is only checked if the user has permission to view the collaboration.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-gc57-xhh5-m94r for updates and patch information.
Vendor References
- GHSA-gc57-xhh5-m94r -
github.com/advisories/GHSA-gc57-xhh5-m94r
CVEs related to QID 995574
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-gc57-xhh5-m94r |
|