Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w297-93hv-q3cx

Опубликовано: 16 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.2
CVSS3: 8.1

Описание

Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships. Attackers can revoke the owner's grant and permanently lock legitimate owners out of objects.

Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships. Attackers can revoke the owner's grant and permanently lock legitimate owners out of objects.

7.2 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 8.1
nvd
1 день назад

Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships. Attackers can revoke the owner's grant and permanently lock legitimate owners out of objects.

7.2 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-862