•  
      request #41476 Artifact permissions are not verified in the Cross Tracker Search widget
    Infos
    #41476
    Kevin Traini (ktraini)
    2025-02-03 09:33
    2025-01-22 10:43
    43130
    Details
    Artifact permissions are not verified in the Cross Tracker Search widget

    In a Cross Tracker Search widget, permissions depending on each artifact context are not correctly verified. This includes permissions like "have access to artifacts they submitted" or permissions defined by the permissions on artifact field.

    Impact

    Users (possibly anonymous ones if the widget is used in the dashboard of a public project) might get access to artifacts they should not see.

    CVSSv3.1 score: 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

    Exploitation

    A tracker with artifacts accessible only to their submitter, if a CrossTrackerSearch widget search on this tracker, users may see artifacts they do not have submitted.

    References

    CWE-280
    CVE-2025-24029

    Cross tracker search
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Kevin Traini (ktraini)
    Closed
    2025-01-22
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2025-01-23 10:38
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    User avatar
    Thomas Gerbet (tgerbet)2025-01-23 09:40

    CVE-2025-24029 has been assigned to this issue.


    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    User avatar
    Thomas Gerbet (tgerbet)2025-01-22 11:35
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    • Reported in version set to All
    User avatar
    Thomas Gerbet (tgerbet)2025-01-22 10:58
    • Summary
      -Artifact permissions are not verified 
      +Artifact permissions are not verified in the Cross Tracker Search widget 
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes