PT-2023-31619 · Unknown · Speckle Server
Fabis94
+1
·
Published
2023-12-14
·
Updated
2023-12-28
·
CVE-2023-50713
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Speckle Server versions prior to 2.17.6
Description
A vulnerability affects users who authorized an application with 'token write' scope or created a Personal Access Token (PAT) with
token write scope. The issue allows a malicious actor to generate further tokens with additional privileges, up to the existing privileges of the user, using a token with only token write scope. This cannot be used to escalate a user's privileges or grant privileges on behalf of other users.Recommendations
For versions prior to 2.17.6, upgrade the server to version 2.17.6 or higher.
Review existing tokens and permanently revoke any unrecognized tokens.
Revoke existing tokens and create new tokens.
Review usage of the account for suspicious activity.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Speckle Server