ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, a…
严重 CVSS 9.1
摘要
ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another workspace by replacing the organizationId parameter in table-management API requests.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://github.com/ToolJet/ToolJet/security/advisories/GHSA-2jhv-482p-4php
- https://www.vulncheck.com/advisories/tooljet-before-3.16.208-cross-workspace-authorization-bypass
- https://github.com/ToolJet/ToolJet/security/advisories/GHSA-2jhv-482p-4php
时间线
- nvd_ingest NVD