A security defect in Foundry's Comments functionality...
Moderate severity
Unreviewed
Published
Jun 6, 2023
to the GitHub Advisory Database
•
Updated Apr 11, 2024
Description
Published by the National Vulnerability Database
Jun 6, 2023
Published to the GitHub Advisory Database
Jun 6, 2023
Last updated
Apr 11, 2024
A security defect in Foundry's Comments functionality resulted in the retrieval of attachments to comments not being gated by additional authorization checks. This could enable an authenticated user to inject a prior discovered attachment UUID into other arbitrary comments to discover it's content.
This defect was fixed in Foundry Comments 2.249.0, and a patch was rolled out to affected Foundry environments. No further intervention is required at this time.
References