Loading HuntDB...

GHSA-fmgc-gvmv-xqxp

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through the XCC CLI. There is no exposure if SSH is disabled or if there are no users assigned optional read-only permissions.

Related CVEs

Key Information

GHSA ID
GHSA-fmgc-gvmv-xqxp
Published
April 28, 2023 9:30 PM
Last Modified
April 4, 2024 3:44 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 15, 2025 6:32 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.