GHSA-rgj7-vg8v-j4wr: Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation
No authentication is required to invoke PUT /api/echo/like/:id. The handler is registered on the public router group. The service increments fav_count for the given echo without checking identity, without a per-user limit, and without CSRF tokens. A remote client can arbitrarily inflate like metrics with repeated requests.
References
Code Behaviors & Features
Detect and mitigate GHSA-rgj7-vg8v-j4wr with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →