Access Control Vulnerability in StackStorm API Affects Authenticated Users
CVE-2018-20345
5.3MEDIUM
What is CVE-2018-20345?
An access control flaw exists in StackStorm API (st2api) that allows authenticated attackers with valid StackStorm accounts to exploit vulnerabilities in the API endpoints. Specifically, by manipulating the /v1/keys query parameters with ?scope=all and ?user=, attackers can access and retrieve datastore items belonging to other users. This issue affects versions prior to 2.9.2 and 2.10.x before 2.10.1, while enterprise editions with RBAC enabled remain unaffected.
