In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://github.com/microcks/microcks/issues/1212 | vendor advisory issue tracking |
https://github.com/microcks/microcks/compare/1.9.1-fix-1...1.10.0 | patch |
https://github.com/microcks/microcks/releases/tag/1.10.0 | release notes |