OSV 1.4.0 · github-reviewed · 修改于 2026-05-12 00:23
发布时间
2026-05-06 11:33
GitHub 审查时间
2026-05-12 00:23
NVD 发布时间
2026-05-06 11:15
源文件
advisories/github-reviewed/2026/05/GHSA-3c93-g9g6-p5j4/GHSA-3c93-g9g6-p5j4.json
An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-privilege user to retrieve the complete ACL policy (roles and permissions) for any user across all organizations by supplying targeted Name and Org parameters via a network request.