DescriptionGuilherme de Almeida Suckevicz
2020-12-17 13:34:50 UTC
In Pulsar manager 0.1.0 version, malicious users will be able to bypass pulsar-manager's admin, permission verification mechanism by constructing special URLs, thereby accessing any HTTP API.
References:
https://www.openwall.com/lists/oss-security/2020/12/17/1
Comment 1Product Security DevOps Team
2020-12-18 19:31:03 UTC