CyberRota Analysis
AI-GeneratedThe vulnerability allows unauthenticated remote users to bypass enable-field restrictions on a repository query parameter, potentially exposing hidden or time-restricted events if the disableOverrideDemand plugin setting is not activated. This could lead to unauthorized access to sensitive information. Organizations using the affected extension should prioritize addressing this issue, particularly those that have not enabled the disableOverrideDemand setting.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user can pass a demand-override parameter to view hidden or time-restricted events, unless the disableOverrideDemand plugin setting is active. Exploitation of this issue requires only that disableOverrideDemand is not enabled.