GMS-2020-5: UNEDITABLE_SCHEMAS and UNEDITABLE_TABLE_DESCRIPTION_MATCH_RULES not respected by frontend service backend
Any install that has UNEDITABLE_SCHEMAS
and/or UNEDITABLE_TABLE_DESCRIPTION_MATCH_RULES
set in the front-end, is being impacted. The value of these properties is ignored if set, allowing any user to modify table and column descriptions, even though the properties imply they shouldn’t be.
References
Detect and mitigate GMS-2020-5 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →