OSV 1.4.0 · github-reviewed · 修改于 2026-07-07 00:52
发布时间
2026-07-07 00:52
GitHub 审查时间
2026-07-07 00:52
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/07/GHSA-xj53-j257-hxvg/GHSA-xj53-j257-hxvg.json
The predicted datapoint write endpoint allows users with only read:assets privileges to write predicted datapoints.
The endpoint:
PUT /api/{realm}/asset/predicted/{assetId}/{attributeName}
accepts write requests from users lacking write:assets.
The implementation appears to check READ_ASSETS while performing a write operation through:
assetPredictedDatapointService.updateValues(...)
A user was created with only:
read:assets
and without write:assets.
The following request succeeded:
PUT /api/master/asset/predicted/4Fr8Pcp7iDjrEmoSUFolvT/temperature
Request body:
[{"x":1779199999001,"y":1337}]
Response:
HTTP/2 204
Database verification confirmed the datapoint was written successfully:
entity_id: 4Fr8Pcp7iDjrEmoSUFolvT
attribute_name: temperature
value: 1337
Users with read-only asset permissions can modify predicted datapoints for assets.