Junglewise Threat Intelligence

Umami authorization bypass in data reset endpoint

Severity: low · CVSS 3.1 · Published 2023-07-28

Executive brief

Umami is an open-source analytics platform that tracks website visitor data. Anyone with a shared analytics dashboard link can completely erase all collected data for that website by exploiting an authorization flaw. This allows users with read-only view permissions to perform destructive actions, resulting in permanent loss of historical analytics data and business intelligence.

Technical details

The vulnerability is an improper authorization check (CWE-285) in the POST /api/websites/{id}/reset endpoint. The endpoint uses the canViewWebsite permission check, which is intended for read-only GET operations, instead of the stricter canUpdateWebsite check required for destructive actions. An attacker with a share link token can extract the token and send a POST request with the x-umami-share-token header to reset all website data. No user interaction or higher privileges are required beyond possessing a share link. The vulnerability affects all versions prior to 2.3.1, which was patched by changing the verification call to canUpdateWebsite.

Affected products

  • Umami Umami < 2.3.1

Timeline

  • 2023-07-27: disclosed
  • 2023-07-28: patched: Fixed in version 2.3.1

References