Description
An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the administrator.
Remediation
References
https://github.com/dataease/dataease/issues/2429
Related Vulnerabilities
CVE-2023-5654 Vulnerability in npm package react-devtools
CVE-2021-28918 Vulnerability in npm package netmask
CVE-2021-29486 Vulnerability in npm package cumulative-distribution-function
CVE-2022-40084 Vulnerability in maven package org.opencrx:opencrx-core
CVE-2022-25872 Vulnerability in npm package fast-string-search