OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in one…
Medium CVSS 6.5
Summary
OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in one realm can send DELETE requests to remove notifications from the master realm or other tenants without authorization checks.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/openremote/openremote/security/advisories/GHSA-rc23-4mmm-4fx9
- https://www.vulncheck.com/advisories/openremote-notification-delete-cross-realm-insecure-direct-object-reference
Timeline
- nvd_ingest NVD