THREAT OPS › Threat News › [GHSA] GHSA-vx2m-jpxr-xv7w (medium) — Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint
[GHSA] GHSA-vx2m-jpxr-xv7w (medium) — Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint
GHSA-vx2m-jpxr-xv7w Severity: medium CVE: None
Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint
## Summary
Cloudreve's file-listing responses hand the client a `context_hint` (UUID) that is meant to speed up follow-up operations. When that hint is replayed on the `file/url` (and `file/thumb`) routes, DBFS caches a `share
Original source: https://github.com/advisories/GHSA-vx2m-jpxr-xv7w