Junglewise Threat Intelligence

CVE-2022-2063: NocoDB improper privilege management

CVE-2022-2063 · Severity: low · CVSS 3.1 · Published 2022-06-14

Technologies: nocodb (npm). Vendors: npm.

Executive brief

NocoDB is a popular open-source database management and collaboration platform. An improper privilege management vulnerability allows attackers to bypass access controls and gain unauthorized access to database resources, potentially compromising the confidentiality and integrity of sensitive data stored within NocoDB instances.

Technical details

The vulnerability stems from improper privilege management (CWE-269) in NocoDB prior to version 0.91.8, allowing attackers to circumvent authorization controls. The vulnerability is reachable over the network without requiring authentication, though user interaction may be involved. By exploiting this flaw, an attacker can gain unauthorized access to database operations and potentially modify or exfiltrate data. The issue has been fixed in version 0.91.8 and later releases.

Affected products

  • NocoDB NocoDB prior to 0.91.8

Timeline

  • 2022-06-14: disclosed
  • 2022-06-13: patched: Fix released in version 0.91.8

References

Related threats