The “Bytebase” application does not restrict low privilege user to access admin “projects“ for which an unauthorized user can view the “projects“ created by “Admin” and the affected endpoint is “/api/project?user=${userId}”.
CVSS
No CVSS.
References
Configurations
History
21 May 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.mend.io/vulnerability-database/CVE-2022-32170 - Exploit, Third Party Advisory | |
CWE |
07 Nov 2023, 03:47
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : unknown |
References |
|
|
Information
Published : 2022-09-28 10:15
Updated : 2025-05-21 14:15
NVD link : CVE-2022-32170
Mitre link : CVE-2022-32170
JSON object : View
Products Affected
bytebase
- bytebase
CWE
No CWE.