Junglewise Threat Intelligence

CVE-2023-27563: n8n privilege escalation in user update endpoint

CVE-2023-27563 · Severity: low · CVSS 3.1 · Published 2023-05-10

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform that allows users to build and run automated tasks. An authenticated user could escalate their privileges by modifying restricted user account fields through an unprotected API endpoint, potentially gaining administrative access or accessing sensitive functionality beyond their permission level.

Technical details

n8n versions prior to 0.216.1 contain a privilege escalation vulnerability in the user update endpoint. The endpoint failed to properly restrict which user profile fields could be modified, allowing an authenticated attacker to update sensitive fields (such as role or permission flags) that should only be modifiable by administrators. The vulnerability requires valid user authentication to exploit. The fix restricts the endpoint to only allow updates to email, firstName, and lastName fields, while protecting sensitive fields from unauthorized modification.

Affected products

  • n8n n8n prior to 0.216.1

Timeline

  • 2023-05-10: disclosed
  • 2023-05-10: patched: Fixed in version 0.216.1

References

Related threats