Executive brief
NL Portal is a platform used by citizens to interact with government services and manage tasks. A security flaw allowed any logged-in user to view, modify, or complete tasks belonging to other citizens by guessing a task ID. This could lead to the exposure of sensitive personal data and the unauthorized submission of official forms.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the Taak V2 implementation of NL Portal. The GraphQL resolver 'submitTaakV2' in 'TaakService' fetched task objects by UUID and processed state transitions without verifying if the authenticated user was the legitimate owner of the task. An attacker with a valid OAuth token could exploit this by providing a victim's task ID to the endpoint, allowing them to read existing form data, overwrite submitted data, and mark tasks as completed. The issue is resolved in version 3.0.1 by implementing an authorization check that validates the task's identification against the authenticated principal.
Affected products
- NL Portal nl-portal-backend-libraries 1.5.0 - 3.0.0
- NL Portal taak 1.5.0 - 3.0.0
Timeline
- 2024-06-04: other: Vulnerable code introduced in commit bb1c1ecf
- 2026-05: disclosed: Discovered during penetration testing engagement
- 2026-06-03: advisory: Initial GitHub Advisory publication
- 2026-07-08: patched: Advisory updated and finalized with patch information