THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-p77j-g7h5-r2vw (high) — GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

[GHSA] GHSA-p77j-g7h5-r2vw (high) — GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

medgithub_advisoriesPublished 2026-08-19

GHSA-p77j-g7h5-r2vw Severity: high CVE: None

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

GeoLens 1.2.4 fixes a set of vulnerabilities, the most serious of which allow authenticated or anonymous users to obtain data and metadata for datasets they are not authorized to access.

### Impact

- **Private record metada

MITRE ATT&CK techniques

Original source: https://github.com/advisories/GHSA-p77j-g7h5-r2vw