PT-2022-20569 · Sourcegraph · Sourcegraph

Published

2022-08-01

·

Updated

2022-08-08

·

CVE-2022-31154

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Sourcegraph versions prior to 3.42
Description The issue allows an authenticated Sourcegraph user to edit Code Monitors owned by any other Sourcegraph user, including editing the trigger and action of the monitor. However, an attacker cannot read the contents of existing code monitors, only override the data.
Recommendations For versions prior to 3.42, update to Sourcegraph 3.42 to resolve the issue, as patching is highly recommended and there are no available workarounds.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-31154
GHSA-5866-HHQ9-9HPC

Affected Products

Sourcegraph