CVE-2024-25106
Last modified
CVE-2024-25106 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulnerability has been identified in the "/api/{org_id}/users/{email_id}" endpoint. EPSS estimates a 0.49% chance of exploitation in the next 30 days.
Description
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulnerability has been identified in the "/api/{org_id}/users/{email_id}" endpoint. This vulnerability allows any authenticated user within an organization to remove any other user from that same organization, irrespective of their respective roles. This includes the ability to remove users with "Admin" and "Root" roles. By enabling any organizational member to unilaterally alter the user base, it opens the door to unauthorized access and can cause considerable disruptions in operations. The core of the vulnerability lies in the `remove_user_from_org` function in the user management system. This function is designed to allow organizational users to remove members from their organization. The function does not check if the user initiating the request has the appropriate administrative privileges to remove a user. Any user who is part of the organization, irrespective of their role, can remove any other user, including those with higher privileges. This vulnerability is categorized as an Authorization issue leading to Unauthorized User Removal. The impact is severe, as it compromises the integrity of user management within organizations. By exploiting this vulnerability, any user within an organization, without the need for administrative privileges, can remove critical users, including "Admins" and "Root" users. This could result in unauthorized system access, administrative lockout, or operational disruptions. Given that user accounts are typically created by "Admins" or "Root" users, this vulnerability can be exploited by any user who has been granted access to an organization, thereby posing a critical risk to the security and operational stability of the application. This issue has been addressed in release version 0.8.0. Users are advised to upgrade.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openobserve | Openobserve | < 0.8.0 |
References
- https://github.com/openobserve/openobserve/security/advisories/GHSA-3m5f-9m66-xgp7Exploit, Third Party Advisory
- https://github.com/openobserve/openobserve/security/advisories/GHSA-3m5f-9m66-xgp7Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-25106?
How severe is CVE-2024-25106?
How do I fix CVE-2024-25106?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-25098Improper Neutralization of Input During Web Page Generation …5.4
- CVE-2024-25099Improper Neutralization of Input During Web Page Generation …5.4
- CVE-2024-25100Deserialization of Untrusted Data vulnerability in WP Swings…9.8
- CVE-2024-25101Improper Neutralization of Input During Web Page Generation …4.8
- CVE-2024-25102This vulnerability exists in AppSamvid software due to the u…7.8
- CVE-2024-25103This vulnerability exists in AppSamvid software due to the u…6.3
- CVE-2024-25107WikiDiscover is an extension designed for use with a CreateW…6.1
- CVE-2024-25108Pixelfed is an open source photo sharing platform. When proc…8.8
- CVE-2024-25109ManageWiki is a MediaWiki extension allowing users to manage…5.4
- CVE-2024-2511Issue summary: Some non-default TLS server configurations ca…5.9
- CVE-2024-25110The UAMQP is a general purpose C library for AMQP 1.0. Durin…8.1
- CVE-2024-25111Squid is a web proxy cache. Starting in version 3.5.27 and p…7.5
Are you affected by CVE-2024-25106?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
