{ "schema_version": "1.4.0", "id": "GHSA-hm89-gqr5-28v6", "modified": "2024-04-04T01:13:12Z", "published": "2022-05-24T16:49:47Z", "aliases": [ "CVE-2019-12782" ], "details": "An authorization bypass vulnerability in pinboard updates in ThoughtSpot 4.4.1 through 5.1.1 (before 5.1.2) allows a low-privilege user with write access to at least one pinboard to corrupt pinboards of another user in the application by spoofing GUIDs in pinboard update requests, effectively deleting them.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" } ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-12782" }, { "type": "WEB", "url": "https://docs.thoughtspot.com/5.1/release/notes.html" }, { "type": "WEB", "url": "https://www.vsecurity.com/download/advisories/201912782-1.txt" }, { "type": "WEB", "url": "https://www.vsecurity.com/resources/advisories.html" } ], "database_specific": { "cwe_ids": [ "CWE-639" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-07-09T16:15:00Z" } }