Incorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a crafted request.
| Software | From | Fixed in |
|---|---|---|
com.baidu.mapp / brcc-core
|
- | 1.2.0.x |
| baidu / brcc | - | 1.2.0.x |