fig. 01 — GHSA-4jqc-jvh2-pxg9, the advisory selected below
// advisories
GHSA-4jqc-jvh2-pxg9
UNKNOWN
A malicious actor with the ability to register entities in the Software Catalog is able to write files to arbitrary paths on the techdocs backend host instance when techdocs.publisher.type is set to local.