PT-2021-19860 · Unknown · Apollos Apps
Published
2021-06-16
·
Updated
2022-07-02
·
CVE-2021-32691
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apollos Apps versions prior to 2.20.0
Description
Apollos Apps is an open source platform for launching church-related apps. In affected versions, new user registrations can access anyone's account by only knowing their basic profile information, such as name, birthday, and gender. This includes all app functionality within the app, as well as any authenticated links to Rock-based webpages, like giving and events.
Recommendations
For versions prior to 2.20.0, update to version 2.20.0 to resolve the issue.
As a temporary workaround, one can patch their server by overriding the
create data source method on the People class. This involves creating a duplicate person and then patching the new person with their profile details, as shown in the provided code snippet.Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apollos Apps