We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is not a namespace Owner or Contributor. The details include: name, description, website, support link and social media links. The same issues existed in /user/namespace/{namespace}/details/logo and allowed a user to change the logo.
Reserved 2025-02-03 | Published 2025-02-19 | Updated 2025-02-19 | Assigner eclipseCWE-285: Improper Authorization
Abdel Adim smaury Oisfi of Shielder
Andrea Cappa zi0Black of Aptos Labs
Leonardo Giovannini maitai
github.com/...penvsx/security/advisories/GHSA-wc7c-xq2f-qp4h
Support options