Executive brief
Curveball a12n-server is an authentication and user management service. A vulnerability in user editing allows any logged-in user to modify other users' accounts without proper authorization checks, potentially leading to account takeover and unauthorized privilege escalation.
Technical details
A newly added HAL-Form for user editing failed to properly enforce admin-only access controls due to incorrect privilege validation. The vulnerability affects versions 0.18.0 through 0.18.1, allowing any authenticated user to modify any other user account, including changing credentials and potentially elevating privileges. The attack requires network access and valid credentials (CWE-269: Improper Access Control / CWE-863: Incorrect Authorization). The vulnerability is patched in version 0.18.2.
Affected products
- Curveball a12n-server 0.18.0 to 0.18.1
Timeline
- 2021-04-16: disclosed: GitHub advisory published
- 2021-04-19: patched: Fix released in version 0.18.2