Improper authorization in the Circles app 0.17.7 causes retaining access when an email address was removed from a circle.
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://hackerone.com/reports/673724 | third party advisory permissions required |
https://nextcloud.com/security/advisory/?id=NC-SA-2019-013 | vendor advisory |