You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The /v/vm endpoints do not check for correct permissions. The code does only check for permission, but not on the target group (group to create the VM in / group that owns the VM).
This allows a user to exploit his permissions. If he has velocity.vm.create on one group, he can create VMs in every group he likes.
The text was updated successfully, but these errors were encountered:
The
/v/vm
endpoints do not check for correct permissions. The code does only check for permission, but not on the target group (group to create the VM in / group that owns the VM).This allows a user to exploit his permissions. If he has
velocity.vm.create
on one group, he can create VMs in every group he likes.The text was updated successfully, but these errors were encountered: