Skip to content

Improper Privilege Management

High
MaKyOtOx published GHSA-x4wp-xvq7-w5vr Dec 14, 2021

Package

No package listed

Affected versions

<1.7.7

Patched versions

1.7.7

Description

Impact

An improper privilege management (IDOR) has been found in PatrowlManager. All imports findings file is placed under /media/imports/<owner_id>/<tmp_file> In that, owner_id is predictable and tmp_file is in format of import_<ownder_id>_<time_created>, for example: import_1_1639213059582.json This filename is predictable and allows anyone without logging in to download all finding import files
This vulnerability is capable of allowing unlogged in users to download all finding imports file

Patches

Update to 1.7.7

Workarounds

Not known

References

Huntr.dev Bug Report by @M0rphling

Severity

High

CVE ID

CVE-2021-43828

Weaknesses

Credits