Description
Xen Orchestra (with xo-web through 5.80.0 and xo-server through 5.84.0) mishandles authorization, as demonstrated by modified WebSocket resourceSet.getAll data is which the attacker changes the permission field from none to admin. The attacker gains access to data sets such as VMs, Backups, Audit, Users, and Groups.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 5.80.0
References
Related Issues
- netmask npm package mishandles octal input data - CVE-2021-29418
- Cross-site Request Forgery (CSRF) in joplin - CVE-2021-23431
- Joplin vulnerable to Cross-site Scripting in notes - CVE-2021-37916
- Cross-site Scripting in pekeupload - CVE-2021-23673
You might also like:
- Tags:
- npm
- xo-web
Anything's wrong? Let us know Last updated on October 19, 2023


