GHSA-8r88-6cj9-9fh5
LOWCVE-2025-48370The library functions getUserById, deleteUser, updateUserById, listFactors and deleteFactor did not require the user supplied values to be valid UUIDs. This could lead to a URL path traversal, resulting in the wrong API function being called.
- Affected
- <= 2.69.1
- Fixed in
- 2.70.0
- Weakness
- CWE-22
- Published
- 2025-05-27
- Source
- github