GHSA-ggf6-638m-vqmg

    Dashboard / Vulnerabilities / GHSA-ggf6-638m-vqmg

    GHSA-ggf6-638m-vqmg

    Published: 15 Sept 2022Last Modified: 21 Aug 2024

    Summary: Netmaker vulnerable to Insufficient Granularity of Access Control

    Details: ### Impact Improper Authorization functions leads to non-privileged users running privileged API calls. If you have added users to your Netmaker platform who whould not have admin privileges, they could use their auth token to run admin-level functions via the API. In addition, differing response codes based on function calls allowed non-users to potentially brute force the determination of names of networks on the system. ### Patches This problem has been patched in v0.15.1. To apply: 1. docker-compose down 2. docker pull gravitl/netmaker:v0.15.1 3. docker-compose up -d ### For more information If you have any questions or comments about this advisory: Email us at [[email protected]](mailto:[email protected]) This vulnerability was brought to our attention by @tweidinger

    Affected packages

    Package

    Name: github.com/gravitl/netmaker

    Purl: pkg:golang/github.com/gravitl/netmaker

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.15.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-ggf6-638m-vqmg | CVE-DB