Access Control Vulnerability in StackStorm API Affects Authenticated Users
CVE-2018-20345

5.3MEDIUM

Key Information:

Vendor

Stackstorm

Vendor
CVE Published:
21 December 2018

What is CVE-2018-20345?

An access control flaw exists in StackStorm API (st2api) that allows authenticated attackers with valid StackStorm accounts to exploit vulnerabilities in the API endpoints. Specifically, by manipulating the /v1/keys query parameters with ?scope=all and ?user=, attackers can access and retrieve datastore items belonging to other users. This issue affects versions prior to 2.9.2 and 2.10.x before 2.10.1, while enterprise editions with RBAC enabled remain unaffected.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.