WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH
Cybersecurity

VU#889462: Casdoor authentication server is vulnerable to authorization bypass

A complex network of cables in a data center with a monitor in the foreground.
Illustrative photo.Photo by panumas nikhomkhai on Pexels

What happened

Note: This issue was fixed in v4.2.0, available at https://github.com/casdoor/casdoor/releases/tag/v4.2.0 Acknowledgements Thank you to Louis Sanchez of Voke Cyber for reporting this vulnerability. Overview Casdoor is an open-source Access Management (IAM) platform used to manage web applications.

The vulnerability allows a non-global organization administrator to perform unauthorized administrative actions against arbitrary organizations by exploiting inconsistent object resolution between the authorization layer and downstream controllers. As a result, authorization is evaluated against one object while the requested operation is executed against another, allowing an authenticated organization administrator ( IsAdmin=true ) to perform unauthorized administrative actions across tenant boundaries.

Therefore, at the time of this publication, no vendor patch is known to be available. Vendor Information One or more vendors are listed for this advisory.

Sources & evidence