PT-2022-20570 · Sourcegraph · Sourcegraph

CVE-2022-31155

·

Published

2022-08-01

·

Updated

2022-08-08

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sourcegraph versions prior to 3.41.0
Description The issue allows an attacker to delete other users’ saved searches due to a bug in the authorization check. It does not allow the reading of other users’ saved searches, only overwriting them with attacker-controlled searches.
Recommendations Update to Sourcegraph version 3.41.0 or later to resolve the issue.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-31155
GHSA-37QP-9JQ6-F6MX

Affected Products

Sourcegraph