Improper authorization control for web services In github.com/forceu/gokapi

Description

Gokapi has privilege escalation with auth token

Impact

A registered user without privileges to create or modify file requests is able to create a short-lived API key that has the permission to do so.

The user must be registered with Gokapi. If you do not have any other users with access to the admin/upload menu, you are not impacted.

Patches

This CVE is patched in v2.2.3

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions