Description
Prior to versions v2.1.10 / v19.1.6 / v19.2.2, CockroachDB was allowing non-authenticated access to privileged HTTP endpoints like/_admin/v1/events that internally operate with the privileges of the CockroachDB user root.
Additionally, it was internally using root privileges to render certain Admin UI pages for logged-in but non-admin users.

