Summary

Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project

Advisory details

Impact

The API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to.

Patches

References

Parts of this issue were independently reported by four reporters:

References