Résumé

Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project

Détails de l’avis

Impact

The API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to.

Patches

References

Parts of this issue were independently reported by four reporters:

Références