{"id":"GHSA-5r3p-6rj5-7937","aliases":[],"url":"https://o3.security/vulnerability/GHSA-5r3p-6rj5-7937","summary":"Bytebase vulnerable to Improper Authentication","details":"### Impact\n- GitLab login allows login by any user.\n- JWT auth token can be derived as long as the server isn't rebooted.\n- Developers can assign issues to non-admin/DBA users.","published":"2026-03-02T17:32:24Z","modified":"2026-03-04T15:12:44.267253Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/bytebase/bytebase","fixedVersion":"1.0.1"}],"fix":{"url":"https://github.com/bytebase/bytebase/commit/a578ed58e478ba5c2dadf8d538ec5c3d39c28461","label":"bytebase/bytebase@a578ed5"},"references":[{"type":"WEB","url":"https://github.com/bytebase/bytebase/security/advisories/GHSA-5r3p-6rj5-7937"},{"type":"WEB","url":"https://github.com/bytebase/bytebase/commit/a578ed58e478ba5c2dadf8d538ec5c3d39c28461"},{"type":"PACKAGE","url":"https://github.com/bytebase/bytebase"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-03-04T15:12:44.267253Z"}}