Skip to content

VulnerabilityResource might bypass ACLs #4809

@stohrendorf

Description

@stohrendorf

Current Behavior

It seems that some endpoints might leak vulnerable software despite ACLs (only looked at the vulnerability endpoint so far). As of right now, this is speculation, and may be closed by DT maintainers at their wish. However, filtering based on ACLs seems to only happen for components most of the time, but not vulnerable software.

Dependency-Track Version

4.12.7

Checklist

Metadata

Metadata

Assignees

No one assigned

    Labels

    access controldefectSomething isn't workingp2Non-critical bugs, and features that help organizations to identify and reduce riskpending release

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions