EIQ-2021-0015#
ID |
EIQ-2021-0015 |
---|---|
CVE |
- |
Description |
Users with only |
Date |
22 September 2021 |
Severity |
2 - MEDIUM |
CVSSv3 score |
CVSSv3 score not available on NIST NVD |
Status |
✅ 2.14.0 |
Assessment |
An attacker with:
can edit and delete any comment on a workspace (“Workspace 1”) as long as they are a collaborator on that workspace. If the other user (“User 2”) writes a comment (“Comment 1”) in that workspace (“Workspace 1”), the attacker can change that comment by sending:
Expected: Users should not be able to modify comments that they did not write. |
Mitigation |
|
Affected versions |
Known issue |
Notes |
N/A |