Authenticated user can add custom tags to any workspace
State | Resolved August 6, 2019 |
Issue ID | c_GOY4yVI |
Asset | Web application |
Bounty | $100 |
Reported at | August 3, 2019 |
Reporter | Undisclosed |
Severity | Low |
Visibility | Limited |
Weakness | CWE 269 - Improper Privilege Management |
Description
Any authenticated user can add custom tags to any workspace via legacy API. The authenticated user must know the workspace ID for this action.