•  
      request #42237 Read permission not enforced on parent tracker in the REST API
    Infos
    #42237
    Joris MASSON (jmasson)
    2025-03-31 10:16
    2025-03-18 19:07
    43913
    Details
    Read permission not enforced on parent tracker in the REST API

    Given a child tracker C with a "parent" tracker P (in the Trackers Hierarchy sense), when I do a GET /api/trackers/{id of C}, even if I do not have permission to access tracker P at all, I can see its name and color in the JSON response.

    Impact

    An attacker could see tracker names that are not supposed to be revealed.
    CVSSv3.1 score: 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)

    References

    CWE 863
    CVE-2025-30155

    Trackers
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Joris MASSON (jmasson)
    Closed
    2025-03-19
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2025-03-20 08:34

    CVE-2025-30155 has been assigned to this issue.


    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    User avatar
    Joris MASSON (jmasson)2025-03-18 19:09
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes