Junglewise Threat Intelligence

CVE-2024-51210: Firepad insecure document access via pad ID

CVE-2024-51210 · Severity: low · CVSS 3.1 · Published 2024-12-04

Vendors: npm.

Executive brief

Firepad is an open-source collaborative text editor that allows multiple users to edit documents in real-time. The vulnerability allows anyone who knows a document's ID to view not only the current content but also the complete history of all text that has ever been pasted into the document. While this may be intentional behavior in some similar products, the lack of proper access controls means sensitive data shared through Firepad documents can be exposed indefinitely. The product is no longer maintained by Firebase, limiting prospects for fixes.

Technical details

Firepad through version 1.5.11 suffers from insufficient access controls (CWE-125, CWE-200) that permit unauthorized document retrieval. The vulnerability allows remote attackers with knowledge of a pad ID to access both current and historical document content via network requests without authentication (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). An attacker can retrieve the complete revision history stored in the underlying Firebase database by exploiting the lack of proper access validation. The attack requires only knowledge of the target pad ID and network reachability to the Firepad service. No patch is available as the project was archived by the maintainer on October 4, 2024, and is no longer actively supported.

Affected products

  • Firebase Firepad through 1.5.11

Timeline

  • 2024-12-04: disclosed: Vulnerability publicly disclosed
  • 2024-10-04: other: Firepad repository archived; product no longer maintained

References