EIQ-2021-0009
| 
     ID  | 
                
     EIQ-2021-0009  | 
        
| 
     CVE  | 
                
     -  | 
        
| 
     Description  | 
                
     Users with only modify ticket-comments and read tickets permissions can edit and delete comments on a Task they are at least a stakeholder on.  | 
        
| 
     Date  | 
                
     17 August 2021  | 
        
| 
     Severity  | 
                
     2 - MEDIUM  | 
        
| 
     CVSSv3 score  | 
                
     CVSSv3 score not available on NIST NVD  | 
        
| 
     Status  | 
                
     
  | 
        
| 
     Assessment  | 
                
     An attacker with: 
 can edit and delete any task comment on that task (“Task_1”) as long as they are at least a “Stakeholder” on that task by sending: 
 Expected: Users should not be able to modify comments that they did not write.  | 
        
| 
     Mitigation  | 
                
     Planned fix, where platform enforces permissions correctly.  | 
        
| 
     Affected versions  | 
                
     2.10.x and earlier  | 
        
| 
     Notes  | 
                
     N/A  | 
        
< Back to all security issues and mitigation actions
In release notes 2.10.1