PT-2026-82067 · Tarsweb · Tarsweb
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TarsWeb versions prior to 3.0.16
Description
TarsWeb incorrectly determines if a request originates from a trusted local caller by relying on a client-controlled header. The
app.js file enables the Koa proxy option without specifying trusted upstream proxies or limiting forwarded hops, causing the reported request address to be taken from the X-Forwarded-For header. In midware/ssoMidware.js, a logic error in a branch handling both the ignored-path list and the ignoreIps allowlist (which includes the loopback address) allows the system to assign an account identity based on the uid query parameter without validating tickets, cookies, or passwords. An attacker can forge the X-Forwarded-For header to mimic the loopback address and provide a uid to gain unauthorized access to any account, including administrators. This grants access to routes for user and role administration, service configuration, and package upload and deployment.Recommendations
Update TarsWeb to version 3.0.16.
Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tarsweb