An improper validation bug allows users who have create privileges to sync a local manifest during application creation. This allows for bypassing the restriction that the manifests come from some approved git/Helm/OCI source.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2024-2643" }