PT-2022-15826 · Tooljet · Tooljet
Published
2022-05-18
·
Updated
2022-05-26
·
CVE-2022-23067
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ToolJet versions v0.5.0 to v1.2.2
Description
The issue allows for token leakage via the Referer header, leading to account takeover. When a user opens an invite link or signup link and then clicks on external links within the page, the password set token or signup token is leaked in the Referer header. An attacker can use these tokens to access the user's account.
Recommendations
For ToolJet versions v0.5.0 to v1.2.2, consider restricting access to external links within the invite link/signup link page until a fix is available. As a temporary workaround, avoid using the invite link/signup link feature to minimize the risk of token leakage.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tooljet