mediumVulnerability

GHSA-5r3p-6rj5-7937

### Impact - GitLab login allows login by any user. - JWT auth token can be derived as long as the server isn't rebooted. - Developers can assign issues to non-admin/DBA users.

Properties

ghsa_id
GHSA-5r3p-6rj5-7937
severity
medium
summary
Bytebase vulnerable to Improper Authentication
cve_id
GHSA-5r3p-6rj5-7937
is_ghsa_only
true
ghsa_published
2026-03-02T17:32:24Z
source_url
https://github.com/advisories/GHSA-5r3p-6rj5-7937
ghsa_updated
2026-03-02T17:32:29Z

Related Entities (3)

AFFECTS (1)

[Software]go/github.com/bytebase/bytebase

HAS_WEAKNESS (1)

[Weakness]Improper Authentication

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph