We found results for “”
WS-2022-0139
Date: May 31, 2022
The deprecated owners.query API does not check object view policy. A user is able to view some information about an owner package which they do not have permission to see by calling this API.
Language: PHP
Severity Score
Severity Score
Weakness Type (CWE)
Improper Access Control
CWE-284CVSS v3
| Base Score: |
|
|---|---|
| Attack Vector (AV): | |
| Attack Complexity (AC): | |
| Privileges Required (PR): | |
| User Interaction (UI): | |
| Scope (S): | |
| Confidentiality (C): | COMPLETE |
| Integrity (I): | PARTIAL |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


