Skip to content

Deleting a collaboration should also delete linked resources

Low
frankcorneliusmartin published GHSA-rf54-7qrr-96j6 Oct 11, 2023

Package

pip vantage6 (pip)

Affected versions

< 3.3.6

Patched versions

None

Description

Impact

When a collaboration is deleted, the linked resources (such as tasks from that collaboration) should be deleted.

This is partly to manage data properly, but also to prevent a potential (but unlikely) side-effect, where if a collaboration with id=10 is deleted, and subsequently a new collaboration is created with id=10, the authenticated users in that collaboration could potentially see results of the deleted collaboration in some cases.

Patches

None

Workarounds

None

References

severity analysis

For more information

If you have any questions or comments about this advisory:

Severity

Low

CVE ID

CVE-2023-41881