OSV 1.4.0 · unreviewed · 修改于 2026-08-25 20:31
发布时间
2026-08-25 20:31
GitHub 审查时间
—
NVD 发布时间
2026-08-25 20:16
源文件
advisories/unreviewed/2026/08/GHSA-6h3p-88p7-m8gp/GHSA-6h3p-88p7-m8gp.json
Ech0 before 4.4.3 protects the PUT /user endpoint with the profile:read scope, a read-only scope, but allows write operations including password changes. An attacker with an admin's profile:read access token can change the admin's password and login to obtain an unrestricted session token that bypasses all scope enforcement.
该公告没有提供结构化的受影响软件包信息。