windmill-cli is vulnerable to Improper Authorization
75
High Risk
Affected versions of this package are vulnerable to improper authorization when accessing secrets across workspaces. The affected endpoints perform incomplete workspace and permission validation, allowing a user with access to one workspace to reference identifiers belonging to another workspace. This insufficient authorization check can allow attackers to access metadata or resources they should not be permitted to view, resulting in cross-workspace information disclosure and unauthorized access.
You are affected if you are using a version that falls within the vulnerable range.
windmill-cli is vulnerable to Improper Authorization in versions 1.561.0 - 1.674.1.
Upgrade the windmill-cli library to a patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant