CVE Vulnerabilities

CVE-2018-20345

Published: Dec 21, 2018 | Modified: Aug 24, 2020
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Incorrect access control in StackStorm API (st2api) in StackStorm before 2.9.2 and 2.10.x before 2.10.1 allows an attacker (who has a StackStorm account and is authenticated against the StackStorm API) to retrieve datastore items for other users by utilizing the /v1/keys ?scope=all and ?user= query filter parameters. Enterprise editions with RBAC enabled are not affected.

Affected Software

Name Vendor Start Version End Version
Stackstorm Stackstorm * 2.9.2 (excluding)
Stackstorm Stackstorm 2.10.0 (including) 2.10.1 (excluding)

References