Description
User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create API with overwrite action.
Problem types
CWE-250: Execution with Unnecessary Privileges
Product status
3.0.0 (semver) before 3.1.1
Credits
Maciej Kawka
References
lists.apache.org/thread/3v58249qscyn1hg240gh8hqg9pb4okcr