🟢 Authenticated privilege escalation in API module via SQL injection in Pinsets

Summary

Once an admin provisions an OAuth application and grants it the low-privilege rest:pinsets:read scope, any holder of that token can read the entire asterisk database.

Authentication with a known OAuth token is required.

Common Vulnerabilities and Exposures (CVE)

Requested

GitHub Security Advisory (GHSA)

GHSA-7wg2-66mh-g7mg

Provider Urgency (choice of: Not Defined, Clear, Green, Amber, or Red)

G - Green

Link to Published GHSA with More Details

Highlights

:green_circle: