Skip to content

Permission check fail allowing untrusted users to modify things they shouldn't be able to modify

High
carolinaisslaying published GHSA-9p8x-5rfp-p2wh Jun 26, 2020

Package

No package listed

Affected versions

5.0.0-Release

Patched versions

5.0.1-Release

Description

Impact

A permission check fails and allows people to edit bots, servers and templates that they don't own and shouldn't have permission to edit.

Patches

This problem was fixed in version 5.0.1-Release which contained multiple other bug fixes including the security patch for this.

Workarounds

Inside of the project you can do a mass replace for req.user.db.assistant to req.user.db.rank.assistant.

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

No known CVE

Weaknesses

No CWEs

Credits