Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://pagure.io/pagure/pull-request/2426 | vendor advisory |
https://pagure.io/pagure/c/c92108097e8ae4702c115ae4702b63d960838e75.patch | patch vendor advisory |