GO-2024-2608

    Dashboard / Vulnerabilities / GO-2024-2608

    GO-2024-2608

    Published: 11 Mar 2024Last Modified: 20 May 2024

    Summary: Minder access control bypass in github.com/stacklok/minder

    Details: A Minder user can use the endpoints to access any repository in the DB, irrespective of who owns the repo and any permissions that user may have. The DB query used checks by repo owner, repo name and provider name (which is always "github"). These query values are not distinct for the particular user, as long as the user has valid credentials and a provider, they can set the repo owner/name to any value they want and the server will return information on this repo. DeleteRepositoryByName uses the same query and a user can delete another user's repo using this technique. The GetArtifactByName endpoint also uses this DB query.

    Affected packages

    Package

    Name: github.com/stacklok/minder

    Purl: pkg:golang/github.com/stacklok/minder

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.0.33

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GO-2024-2608 | CVE-DB