Skip to content
Toggle navigation
Sign up
Product
Actions
Automate any workflow
Packages
Host and manage packages
Security
Find and fix vulnerabilities
Codespaces
Instant dev environments
Copilot
Write better code with AI
Code review
Manage code changes
Issues
Plan and track work
Discussions
Collaborate outside of code
Explore
All features
Documentation
GitHub Skills
Blog
Solutions
For
Enterprise
Teams
Startups
Education
By Solution
CI/CD & Automation
DevOps
DevSecOps
Case Studies
Customer Stories
Resources
Open Source
GitHub Sponsors
Fund open source developers
The ReadME Project
GitHub community articles
Repositories
Topics
Trending
Collections
Pricing
In this repository
All GitHub
↵
Jump to
↵
No suggested jump to results
In this repository
All GitHub
↵
Jump to
↵
In this organization
All GitHub
↵
Jump to
↵
In this repository
All GitHub
↵
Jump to
↵
Sign in
Sign up
{{ message }}
datahub-project
/
datahub
Public
Notifications
Fork
2.2k
Star
7.7k
Code
Issues
88
Pull requests
83
Actions
Projects
1
Security
Insights
More
Code
Issues
Pull requests
Actions
Projects
Security
Insights
System account impersonation (`GHSL-2022-079`)
High
david-leifker
published
GHSA-qgp2-qr66-j8r8
Jan 6, 2023
Package
datahub-frontend
(Java)
Affected versions
<v0.8.45
Patched versions
v0.8.45
Description
Impact
This issue may lead to an Authorization Bypass
Severity
High
8.2
/ 10
CVSS base metrics
Attack vector
Network
Attack complexity
High
Privileges required
Low
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
CVE ID
CVE-2023-25559
Weaknesses
No CWEs
Credits
pwntester
Analyst
p-
Analyst
Kwstubbs
Analyst
sylwia-budzynska
Analyst
artsploit
Analyst
jorgectf
Analyst
You can’t perform that action at this time.
You signed in with another tab or window.
Reload
to refresh your session.
You signed out in another tab or window.
Reload
to refresh your session.
Impact
This issue may lead to an Authorization Bypass