Executive brief
Umami is an open-source analytics platform that tracks website visitor data. Anyone with a shared analytics dashboard link can completely erase all collected data for that website by exploiting an authorization flaw. This allows users with read-only view permissions to perform destructive actions, resulting in permanent loss of historical analytics data and business intelligence.
Technical details
The vulnerability is an improper authorization check (CWE-285) in the POST /api/websites/{id}/reset endpoint. The endpoint uses the canViewWebsite permission check, which is intended for read-only GET operations, instead of the stricter canUpdateWebsite check required for destructive actions. An attacker with a share link token can extract the token and send a POST request with the x-umami-share-token header to reset all website data. No user interaction or higher privileges are required beyond possessing a share link. The vulnerability affects all versions prior to 2.3.1, which was patched by changing the verification call to canUpdateWebsite.
Affected products
- Umami Umami < 2.3.1
Timeline
- 2023-07-27: disclosed
- 2023-07-28: patched: Fixed in version 2.3.1