Executive brief
Mezzanine is a Django-based content management system used to build and manage websites. Attackers can manipulate HTTP Host headers to bypass access controls, potentially allowing unauthorized access to restricted content or administrative functions. This could lead to unauthorized viewing, modification, or deletion of website content, or account takeover depending on what resources are protected by the vulnerable access control checks.
Technical details
The vulnerability is an incorrect access control issue in Mezzanine v6.0.0 and earlier versions where Host header validation is insufficient or missing in access control checks. An attacker can send specially crafted HTTP requests with a manipulated Host header to bypass authentication or authorization mechanisms. The vulnerability is remotely exploitable without authentication and requires only network access to a Mezzanine instance. By exploiting this flaw, an attacker can gain unauthorized access to protected resources or functionality that should be restricted. While a proof-of-concept has been documented, official patch status is not clearly indicated in available sources.
Affected products
- Mezzanine Mezzanine CMS 0.0 through 6.0.0
Timeline
- 2024-02-28: disclosed
- 2024-01-10: other: Vulnerability discovered and reported