Skip to content

Security vulnerability in the Organisation Invite mechanism

Critical
d4nt published GHSA-742c-57p7-mpg9 Nov 29, 2019

Package

No package listed

Affected versions

< 3.0.99

Patched versions

3.0.99

Description

Impact

This allows an attacker to gain complete access to any QueryTree organization if they know the organisation ID.

Patches

The problem is fixed in 3.0.99

References

For more information

If you have any questions or comments about this advisory please open an issue in the QueryTree github

Severity

Critical

CVE ID

CVE-2019-19249

Weaknesses

No CWEs