Lucene search

K
osvGoogleOSV:CVE-2022-21660
HistoryFeb 09, 2022 - 8:15 p.m.

CVE-2022-21660

2022-02-0920:15:12
Google
osv.dev
8
cve-2022-21660
gin-vue-admin
backstage management
vue
gin
privilege escalation
authentication

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

32.8%

Gin-vue-admin is a backstage management system based on vue and gin. In versions prior to 2.4.7 low privilege users are able to modify higher privilege users. Authentication is missing on the setUserInfo function. Users are advised to update as soon as possible. There are no known workarounds.

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

32.8%

Related for OSV:CVE-2022-21660