Netmaker vulnerable to Insufficient Granularity of Access Control
Package
Affected versions
< 0.15.1
Patched versions
0.15.1
Description
Published by the National Vulnerability Database
Sep 9, 2022
Published to the GitHub Advisory Database
Sep 15, 2022
Reviewed
Sep 15, 2022
Last updated
Jun 27, 2023
Impact
Improper Authorization functions leads to non-privileged users running privileged API calls. If you have added users to your Netmaker platform who whould not have admin privileges, they could use their auth token to run admin-level functions via the API.
In addition, differing response codes based on function calls allowed non-users to potentially brute force the determination of names of networks on the system.
Patches
This problem has been patched in v0.15.1. To apply:
For more information
If you have any questions or comments about this advisory:
Email us at info@netmaker.io
This vulnerability was brought to our attention by @tweidinger
References