Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SECURITY] 4 Broken Access Control Vulnerabilities #4593

Open
m10x opened this issue Nov 22, 2024 · 8 comments
Open

[SECURITY] 4 Broken Access Control Vulnerabilities #4593

m10x opened this issue Nov 22, 2024 · 8 comments
Labels
bug: confirmed bug Something isn't working

Comments

@m10x
Copy link

m10x commented Nov 22, 2024

A few minutes ago I've emailed you the details to one high risk broken access control vulnerability and will now write you the details to three more (but low to lower medium risk) broken access control vulnerabilities.

@m10x
Copy link
Author

m10x commented Nov 22, 2024

I've sent an email for each of the 4 vulns :)

@hay-kot
Copy link
Collaborator

hay-kot commented Nov 23, 2024

Thanks for the report! I've reviewed the info and passed it along to the other maintainers, we'll follow up once we've fixed that issue.

Copy link
Contributor

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@github-actions github-actions bot added the stale label Dec 24, 2024
@m10x
Copy link
Author

m10x commented Dec 24, 2024

Hi, any update? :)

@github-actions github-actions bot removed the stale label Dec 25, 2024
@michael-genson michael-genson added bug Something isn't working bug: confirmed labels Dec 25, 2024
@michael-genson
Copy link
Collaborator

Hey there! These are still being worked on, thank you for following up!

@Madj42
Copy link

Madj42 commented Jan 14, 2025

I have to say, I'm a little more than concerned that these vulnerabilities haven't been fixed yet. Is there any plan to have this in a release soon?

@michael-genson
Copy link
Collaborator

These are actively being worked on. All four reported vulnerabilities require authenticated access, and there are no known vulnerabilities exploitable by unauthenticated users.

While we intend to resolve the reported issues, please see our security documentation which addresses best practices which cover the reported issues.

@m10x
Copy link
Author

m10x commented Jan 23, 2025

I just tested the 3 fixes and can confirm that 3 of the 4 reported vulnerabilities are fixed :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug: confirmed bug Something isn't working
Projects
None yet
Development

No branches or pull requests

4 participants