Skip to content

Investigate potential security vulnerability - Unauthorized Access To Add Segments In All User Accounts Via IDOR #6914

@asaphko

Description

@asaphko

We received a report that indicates a potential vulnerability:

"The application has a functionality that allows users to add segments.
However, it does not implement an authorization check for the "project"
parameter, which allows users to add segments in all users account by
replacing the "project" parameter.

By exploiting this vulnerability, an attacker can add segments. As the
"project" parameter is numeric, the Attacker can do a brute force attack on
this endpoint. As a result, an attacker account can add segments in all
users account."

Metadata

Metadata

Assignees

Labels

p2priority label used for issues tagged with security

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions