Description
An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the administrator.
Remediation
References
https://github.com/dataease/dataease/issues/2429
Related Vulnerabilities
CVE-2021-32819 Vulnerability in npm package squirrelly
CVE-2022-22984 Vulnerability in npm package @snyk/snyk-hex-plugin
CVE-2022-21192 Vulnerability in npm package serve-lite
CVE-2021-23509 Vulnerability in npm package json-ptr
CVE-2020-15262 Vulnerability in npm package webpack-subresource-integrity