Description
Xen Orchestra (with xo-web through 5.80.0 and xo-server through 5.84.0) mishandles authorization, as demonstrated by modified WebSocket resourceSet.getAll data is which the attacker changes the permission field from none to admin. The attacker gains access to data sets such as VMs, Backups, Audit, Users, and Groups.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 5.80.0
References
Could your website be exposed too?
SmartScanner can check your website for Xen Orchestra Mishandles Authorization and gives you actionable findings to investigate.
Start a free scanRelated Issues
- netmask npm package mishandles octal input data - CVE-2021-29418
- Cross-site Request Forgery (CSRF) in joplin - CVE-2021-23431
- Joplin vulnerable to Cross-site Scripting in notes - CVE-2021-37916
- Cross-site Scripting in pekeupload - CVE-2021-23673


