Executive brief
Logo Cloud, a cloud-based business management platform, contains a security flaw that allows authorized users to access data or resources they are not permitted to see. By manipulating specific identifiers in web requests, a high-privileged user could bypass intended restrictions to view sensitive information or cause resource leaks. This could lead to unauthorized data exposure and potential operational disruptions within the cloud environment.
Technical details
An authorization bypass vulnerability (CWE-639) exists in Logo Software Inc. Logo Cloud versions prior to 0.67. The flaw stems from insufficient validation of user-controlled keys, which allows an attacker to perform 'forceful browsing' to access unauthorized resources. While the attack requires high privileges (PR:H), it can be executed over the network without user interaction. Successful exploitation enables the attacker to bypass authorization checks, potentially leading to sensitive resource exposure and resource leaks. The issue is addressed in version 0.67.
Affected products
- Logo Software Inc. Logo Cloud before 0.67
Timeline
- 2025-10-06: disclosed
- 2025-10-06: advisory