PT-2026-67878 · Baserow · Baserow
CVSS v3.1
2.2
Low
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Baserow versions prior to 2.3.3
Description
An issue in the Inactive Non-Staff User Handler component allows for improper authorization through the manipulation of the
BaserowImpersonateAuthTokenSerializer() function located in the backend/src/baserow/api/admin/users/serializers.py file. This flaw enables remote exploitation, although the attack complexity is high and exploitation is considered difficult. The project maintainer has noted that while a token may be issued for a deactivated user, the endpoints may not actually function, suggesting the issue may behave more like a bug than a security flaw.Recommendations
Update to version 2.3.3.
Exploit
Fix
Incorrect Privilege Assignment
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Baserow