A user with a `default` role given to them by the admin...
High severity
Unreviewed
Published
Feb 26, 2024
to the GitHub Advisory Database
•
Updated Mar 17, 2026
Description
Published by the National Vulnerability Database
Feb 26, 2024
Published to the GitHub Advisory Database
Feb 26, 2024
Last updated
Mar 17, 2026
A user with a
defaultrole given to them by the admin can sentDELETEHTTP requests toremove-folderandremove-documentto delete folders and source files from the instance even when their role should explicitly not allow this action on the system.References