#683 SEC-03: Artifact download endpoint lacks authentication

closed critical Created 2025-12-25 02:55 · Updated 2025-12-25 03:16

Description

Edit
Location: api/blueprints/v1/artifacts.py:260. Issue: Artifacts can be downloaded by anyone who knows the SHA-256 hash. Hash values may leak via logs or API responses. Fix: Add @require_permission decorator OR implement signed URLs with expiration.

Comments

Loading comments...

Context

Loading context...

Audit History

View All
Loading audit history...