Improper Privilege Management in rhizome-conifer/conifer
Valid
Reported on
Dec 23rd 2021
Description
Hi there, I would like to report an improper privilege escalation in conifer. Any user can view all recordings of other users.
Proof of Concept
- Go to https://conifer.rhizome.org/ and register 2 accounts, let's call it user1 and user2
- Use user1 and create a collection, let's name this collection1
- Login as user2 and go to this link
https://conifer.rhizome.org/api/v1/recordings?user=<user1>&coll=collection1
- See that you can view all recordings of user1.
Impact
This vulnerability is capable of viewing all users recordings.
We are processing your report and will contact the
rhizome-conifer/conifer
team within 24 hours.
a year ago
We have contacted a member of the
rhizome-conifer/conifer
team and are waiting to hear back
a year ago
We have sent a
follow up to the
rhizome-conifer/conifer
team.
We will try again in 7 days.
a year ago
We have sent a
second
follow up to the
rhizome-conifer/conifer
team.
We will try again in 10 days.
a year ago
We have sent a
third and final
follow up to the
rhizome-conifer/conifer
team.
This report is now considered stale.
a year ago
The fix bounty has been dropped
This vulnerability will not receive a CVE
to join this conversation