PT-2026-69832 · Git+1 · Opensign+1
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
opensignserver versions prior to 2.37.1
Description
An authentication bypass exists in the
getsignedurl Parse cloud function. The function fails to perform the isAuthenticated check when a docId parameter is provided, regardless of whether the ID corresponds to a valid document. This allows an unauthenticated remote attacker to generate file access tokens signed with the MASTER KEY for any stored file by supplying an arbitrary string to the docId variable.Recommendations
Update opensignserver to version 2.37.1 or later.
As a temporary mitigation, restrict access to the
getsignedurl function.Exploit
Fix
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opensign
Opensignserver