GHSA-62g2-q3w2-xf47CriticalCVSS 9.6
An authenticated attacker can spoof another GUI user's identity by sending their request with the...
🔗 CVE IDs covered (1)
📋 Description
An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header "Grpc-Metadata-USER". This can lead to an account takeover attack from a user with low privileges to administrator.