Authenticated user can add custom tags to any workspace

State Resolved
August 6, 2019
Issue ID c_GOY4yVI
Asset Web application
Bounty $100
Reported at August 3, 2019
Reporter Undisclosed
Severity Low
Visibility Limited
Weakness CWE 269 - Improper Privilege Management

Description

Any authenticated user can add custom tags to any workspace via legacy API. The authenticated user must know the workspace ID for this action.


The rest of the report is undisclosed.