PT-2023-23589 · Gravitl · Netmaker

Iamnoooob

+1

·

Published

2023-08-24

·

Updated

2026-05-18

·

CVE-2023-32078

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Netmaker versions prior to 0.17.1 Netmaker versions 0.18.0 through 0.18.5
Description An Insecure Direct Object Reference (IDOR) vulnerability was found in the user update function, allowing an attacker to update another user's password by specifying their username.
Recommendations For versions prior to 0.17.1, upgrade to version 0.17.1 or later. For versions 0.18.0 through 0.18.5, upgrade to version 0.18.6 or later. If using version 0.17.1, run docker pull gravitl/netmaker:v0.17.1 and docker-compose up -d to switch to the patched users. As a temporary workaround for version 0.17.1, pull the latest docker image of the backend and restart the server.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2023-32078
GHSA-256M-J5QW-38F4
GO-2023-2023

Affected Products

Netmaker