THREAT OPS › Threat News › [GHSA] GHSA-p77j-g7h5-r2vw (high) — GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
[GHSA] GHSA-p77j-g7h5-r2vw (high) — GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
GHSA-p77j-g7h5-r2vw Severity: high CVE: None
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
GeoLens 1.2.4 fixes a set of vulnerabilities, the most serious of which allow authenticated or anonymous users to obtain data and metadata for datasets they are not authorized to access.
### Impact
- **Private record metada
MITRE ATT&CK techniques
Original source: https://github.com/advisories/GHSA-p77j-g7h5-r2vw