An improper API access control issue has been identified, allowing low-privilege, authenticated users to create and update data type information that should be restricted to users with access to the settings section.
Will be patched in 14.3.3 and 15.2.3.
None available.
{
"github_reviewed": true,
"severity": "MODERATE",
"cwe_ids": [
"CWE-285",
"CWE-863"
],
"nvd_published_at": "2025-03-11T16:15:17Z",
"github_reviewed_at": "2025-03-11T15:27:28Z"
}