blob: 834ae7da35c1f3a150e1195fabe039a2054b2d2b [file] [log] [blame]
id: GO-2024-3325
modules:
- module: github.com/kcp-dev/kcp
versions:
- fixed: 0.26.1
vulnerable_at: 0.26.0
summary: kcp's impersonation allows access to global administrative groups in github.com/kcp-dev/kcp
ghsas:
- GHSA-c7xh-gjv4-4jgv
references:
- advisory: https://github.com/kcp-dev/kcp/security/advisories/GHSA-c7xh-gjv4-4jgv
- fix: https://github.com/kcp-dev/kcp/commit/24ab5d4dc35ddff98a2e5fdc236e1681f03283ec
- fix: https://github.com/kcp-dev/kcp/pull/3206
source:
id: GHSA-c7xh-gjv4-4jgv
created: 2024-12-11T16:19:33.742126-05:00
review_status: UNREVIEWED