EIQ-2021-0015
ID |
EIQ-2021-0015 |
CVE |
- |
Description |
Users with only modify workspace-comments and read workspace permissions can edit and delete comments in workspaces where they are set as a collaborator. |
Date |
22 September 2021 |
Severity |
2 - MEDIUM |
CVSSv3 score |
CVSSv3 score not available on NIST NVD |
Status |
Planned |
Assessment |
An attacker with:
can edit and delete any comment on a workspace (“Workspace 1”) as long as they are a collaborator on that workspace. If the other user (“User 2”) writes a comment (“Comment 1”) in that workspace (“Workspace 1”), the attacker can change that comment by sending:
Expected: Users should not be able to modify comments that they did not write. |
Mitigation |
Planned fix, where platform enforces permissions correctly. |
Affected versions |
2.10.x and earlier |
Notes |
N/A |
< Back to all security issues and mitigation actions
In release notes 2.11.0