The Contour Service was not checking that users had...
Moderate severity
Unreviewed
Published
Jun 27, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Jun 27, 2023
Published to the GitHub Advisory Database
Jun 27, 2023
Last updated
Apr 4, 2024
The Contour Service was not checking that users had permission to create an analysis for a given dataset. This could allow an attacker to clutter up Compass folders with extraneous analyses, that the attacker would otherwise not have permission to create.
References