dashy
dashy copied to clipboard
[BUG] Unauthorized access
Environment
Self-Hosted (Docker)
System
No response
Version
2.1.1
Describe the problem
the "disableConfiguration" has set to "true" but the configuration is able to change via http request
Additional info
No response
Please tick the boxes
- [X] You have explained the issue clearly, and included all relevant info
- [X] You are using a supported version of Dashy
- [X] You've checked that this issue hasn't already been raised
- [X] You've checked the docs and troubleshooting guide
- [X] You agree to the code of conduct
CWE-ID: CWE-284 (Improper Access Control) Assigned CVE-2023-5916
Seems like a Duplicate of #668 Please close this.