PT-2023-33070 · Saltcorn+1 · Saltcorn+1

Published

2023-07-27

·

Updated

2023-07-27

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Saltcorn versions prior to 0.8.7
Description The issue allows an untrusted user with admin rights to a tenant instance to install a plugin that can access information from other tenants, potentially compromising all tenants of the installation. This can be achieved by publishing an unapproved plugin to NPM and then installing it in a tenant. The vulnerability is not fully fixed in version 0.8.7. The estimated number of potentially affected devices is not specified.
Recommendations For Saltcorn versions prior to 0.8.7, consider disabling the plugin installation feature for tenants until a patch is available. Restrict access to the available plugins configuration to prevent tenant admins from installing unsafe plugins. As a temporary workaround, manually review and approve all plugins before they are installed in any tenant instance. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GHSA-WXF3-4FVJ-VQQX

Affected Products

Npm
Saltcorn