PT-2022-20569 · Sourcegraph · Sourcegraph
Published
2022-08-01
·
Updated
2022-08-08
·
CVE-2022-31154
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Sourcegraph versions prior to 3.42
Description
The issue allows an authenticated Sourcegraph user to edit Code Monitors owned by any other Sourcegraph user, including editing the trigger and action of the monitor. However, an attacker cannot read the contents of existing code monitors, only override the data.
Recommendations
For versions prior to 3.42, update to Sourcegraph 3.42 to resolve the issue, as patching is highly recommended and there are no available workarounds.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcegraph