The main issue with the vulnerability is that it allows projects to run scripts that can literally delete or edit projects in your account. I could make a project, that, when run, copies it's source code to all of your projects and then auto publishes them to the public gallery, propagating the worm across cdo wiping millions of projects.

Awards

    a month later
    16 days later
    16 days later

    @[WUT] Adam lookie what I found.

    Awards

    • â’¸ 0.1 from Varrience
      Comment: what matters more is if you can actually update those credentials to make additional requests of which permissions like that are probably behind admin privlages

    Chat