PT-2021-21341 · 1Password · 1Password Connect Server
Published
2021-07-15
·
Updated
2021-08-05
·
CVE-2021-36758
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
1Password Connect server version 1.2 and earlier
Description
The issue is related to missing validation checks in the 1Password Connect server, allowing users to create Secrets Automation access tokens for privilege escalation. Malicious users authorized to create these tokens can access beyond their authorized limits, but only within the existing authorizations of the Secret Automation the token is created in.
Recommendations
For versions prior to 1.2, update to version 1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the Secrets Automation access token creation feature to minimize the risk of exploitation.
Fix
Incorrect Authorization
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
1Password Connect Server