GHSA-mp76-7w5v-pr75
HIGHCVE-2024-28181TurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some
- Affected
- >= 0.2.0, < 0.2.2, < 0.1.3
- Fixed in
- 0.2.2
- Weakness
- CWE-74
- Published
- 2024-03-15
- Source
- github