Skip to content

Improper API Access Control in CLA assistant

Moderate
michael-spengler published GHSA-4h6f-c68c-pxhr Jan 12, 2021

Package

No package listed

Affected versions

< 2.8.5

Patched versions

2.8.5

Description

Impact

Due to improper access control an authenticated user could access api endpoints which are not intended to be used by the user. This could impact the integrity of the application.

Patches

The issue has been fixed in this version v2.8.5.

Workarounds

There are no workarounds.

Severity

Moderate

CVE ID

CVE-2021-21471

Weaknesses

No CWEs