PT-2023-31619 · Unknown · Speckle Server

Fabis94

+1

·

Published

2023-12-14

·

Updated

2023-12-28

·

CVE-2023-50713

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Speckle Server versions prior to 2.17.6
Description A vulnerability affects users who authorized an application with 'token write' scope or created a Personal Access Token (PAT) with token write scope. The issue allows a malicious actor to generate further tokens with additional privileges, up to the existing privileges of the user, using a token with only token write scope. This cannot be used to escalate a user's privileges or grant privileges on behalf of other users.
Recommendations For versions prior to 2.17.6, upgrade the server to version 2.17.6 or higher. Review existing tokens and permanently revoke any unrecognized tokens. Revoke existing tokens and create new tokens. Review usage of the account for suspicious activity.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-50713
GHSA-XPF3-5Q5X-3QWH

Affected Products

Speckle Server