4gaBoards — это система досок для управления проектами в реальном времени. До версии 3.3.8 4gaBoards уязвим для предварительного захвата учетной записи, если включены RegistrationEnabled, localRegistrationEnabled и ssoRegistrationEnabled и настроен единый вход Google, GitHub, Microsoft или OIDC. Конечная точка POST /api/register разрешает создание непроверенной локальной учетной записи с адресом электронной почты жертвы, а POST /api/access-tokens позволяет этой учетной записи проходить аутентификацию, пока isVerified имеет значение false.
Во время первого входа жертвы в единый вход: server/api/helpers/users/get-create-one-for-github-sso.js, server/api/helpers/users/get-create-one-for-google-sso.js, server/api/helpers/users/get-create-one-for-microsoft-sso.js и server/api/helpers/users/get-create-one-for-oidc-sso.js найдите учетную запись, контролируемую злоумышленником, по электронной почте и свяжите проверенный идентификатор SSO, не подтверждая владение локальной учетной записью. Злоумышленник может сохранить доступ к связанной учетной записи с помощью локального пароля и получить проекты, данные и разрешения жертвы. Эта проблема исправлена в версии 3.3.8.
Показать оригинальное описание (EN)
4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, Microsoft, or OIDC SSO is configured. The POST /api/register endpoint permits creation of an unverified local account with a victim's email address, and POST /api/access-tokens permits that account to authenticate while isVerified is false. During the victim's first SSO login, server/api/helpers/users/get-create-one-for-github-sso.js, server/api/helpers/users/get-create-one-for-google-sso.js, server/api/helpers/users/get-create-one-for-microsoft-sso.js, and server/api/helpers/users/get-create-one-for-oidc-sso.js find the attacker-controlled account by email and link the verified SSO identity without confirming ownership of the local account. The attacker can retain local-password access to the linked account and obtain the victim's projects, data, and permissions. This issue is fixed in version 3.3.8.
Характеристики атаки
Последствия
Строка CVSS v3.1