PT-2026-5019 · Git+1 · Taiga-Back
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Taiga versions prior to 6.10.2
Description
Missing authorization allows unauthenticated remote attackers to create default due-date records in any project. This is achieved by exploiting unprotected POST endpoints on the user-story, task, and issue due-date API viewsets. By supplying an arbitrary project identifier, attackers can bypass permission checks and apply the
AllowAny default, preventing project administrators from initializing due dates themselves.Recommendations
Update to version 6.10.2 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Taiga-Back