{"id":"GHSA-5r3p-6rj5-7937","summary":"Bytebase vulnerable to Improper Authentication","details":"### Impact\n- GitLab login allows login by any user.\n- JWT auth token can be derived as long as the server isn't rebooted.\n- Developers can assign issues to non-admin/DBA users.","modified":"2026-03-04T15:12:44.267253Z","published":"2026-03-02T17:32:24Z","database_specific":{"cwe_ids":["CWE-287"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-03-02T17:32:24Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/bytebase/bytebase/security/advisories/GHSA-5r3p-6rj5-7937"},{"type":"WEB","url":"https://github.com/bytebase/bytebase/commit/a578ed58e478ba5c2dadf8d538ec5c3d39c28461"},{"type":"PACKAGE","url":"https://github.com/bytebase/bytebase"}],"affected":[{"package":{"name":"github.com/bytebase/bytebase","ecosystem":"Go","purl":"pkg:golang/github.com/bytebase/bytebase"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-5r3p-6rj5-7937/GHSA-5r3p-6rj5-7937.json","last_known_affected_version_range":"\u003c= 1.0.0"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U"}]}