Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade amundsen-frontend
to version 3.1.0 or higher.
amundsen-frontend is a Web UI for Amundsen
Affected versions of this package are vulnerable to Insecure Permissions. Any install that has UNEDITABLE_SCHEMAS
and/or UNEDITABLE_TABLE_DESCRIPTION_MATCH_RULES
set in the front-end, is being impacted. The value of these properties is ignored if set, allowing any user to modify table and column descriptions, even though the properties imply they shouldn't be.