Junglewise Threat Intelligence

CVE-2023-35167: Remult apiPrefilter access control bypass in entity by Id requests

CVE-2023-35167 · Severity: low · CVSS 3.1 · Published 2023-06-20

Vendors: npm.

Executive brief

Remult is a framework for building full-stack applications with ORM capabilities. A security flaw allows attackers to bypass access control filters when fetching, updating, or deleting resources by ID if the application uses a function-based apiPrefilter for authorization. An attacker who discovers the ID of a protected resource can access, modify, or delete it despite authorization rules.

Technical details

The vulnerability is an access control bypass in Remult's entity API filtering mechanism. When EntityOptions.apiPrefilter is set to a function that returns a filter object, this filter is not properly applied to API requests that target a resource by its unique identifier (ID), even though it is correctly applied to list and other API operations. An unauthenticated or low-privileged attacker who knows the ID of an entity instance can send direct requests to fetch, update, or delete that resource, bypassing the intended authorization filter. The issue is resolved in version 0.20.6; workarounds include using a filter object instead of a function for apiPrefilter.

Affected products

  • Remult Remult < 0.20.6

Timeline

  • 2023-06-20: disclosed
  • 2023-06-20: patched: Version 0.20.6 released

References