Back

MEDIUM

Improper Authorization in /user/namespace/{namespace}/details

Published Feb 19, 2025

Description

In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is not a namespace Owner or Contributor. The details include: name, description, website, support link and social media links. The same issues existed in /user/namespace/{namespace}/details/logo and allowed a user to change the logo.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner eclipse
Published Feb 19, 2025
Updated Feb 19, 2025
Reserved Feb 3, 2025
CISA Vulnrichment
Updated Feb 19, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a