[GHSA-8vrh-3pm2-v4v6] FileBrowser Quantum: Password Protection Not Enforced on Shared File Links #7353
Conversation
|
Hi there @gtsteffaniak! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
|
👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the |
|
Hi, I was wondering if we could get this merged. I see someone that works on the advisory mentioned this in another PR and requested @gtsteffaniak s review, however he has not responded in almost 2 weeks. |
Updates
Comments
I am the original creator of this vulnerability, I think that adding CWE-602 would describe a core issue that made this security vulnerability possible