{"id":"GHSA-256m-j5qw-38f4","summary":"Netmaker IDOR Allows User to Update Other User's Password","details":"### Impact\nAn IDOR vulnerability was found in the user update function. By specifying another user's username it is possible to update the other user's password.\n\n### Patches\nIssue is patched in 0.17.1, and fixed in 0.18.6+.\n\nIf Users are using 0.17.1, they should run \"docker pull gravitl/netmaker:v0.17.1\" and \"docker-compose up -d\". This will switch them to the patched users\n\nIf users are using v0.18.0-0.18.5, they should upgrade to v0.18.6 or later.\n\n### Workarounds\nIf using 0.17.1, can just pull the latest docker image of backend and restart server.\n\n### References\nCredit to Project Discovery, and in particular https://github.com/rootxharsh , https://github.com/iamnoooob, and https://github.com/projectdiscovery","aliases":["CVE-2023-32078","GO-2023-2023"],"modified":"2024-08-21T14:42:12.662510Z","published":"2023-08-25T18:41:16Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2023-08-25T18:41:16Z","nvd_published_at":"2023-08-24T22:15:10Z","cwe_ids":["CWE-639"]},"references":[{"type":"WEB","url":"https://github.com/gravitl/netmaker/security/advisories/GHSA-256m-j5qw-38f4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-32078"},{"type":"WEB","url":"https://github.com/gravitl/netmaker/pull/2158"},{"type":"WEB","url":"https://github.com/gravitl/netmaker/commit/b3be57c65bf0bbfab43b66853c8e3637a43e2839"},{"type":"PACKAGE","url":"https://github.com/gravitl/netmaker"}],"affected":[{"package":{"name":"github.com/gravitl/netmaker","ecosystem":"Go","purl":"pkg:golang/github.com/gravitl/netmaker"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.17.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/08/GHSA-256m-j5qw-38f4/GHSA-256m-j5qw-38f4.json"}},{"package":{"name":"github.com/gravitl/netmaker","ecosystem":"Go","purl":"pkg:golang/github.com/gravitl/netmaker"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.18.0"},{"fixed":"0.18.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/08/GHSA-256m-j5qw-38f4/GHSA-256m-j5qw-38f4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}