CVE-2023-32079High· 8.8▾ TwilightNetmaker Vulnerable to Privilege Escalation From Non Admin To Admin User
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.9%
A Mass assignment vulnerability was found allowing a non-admin user to escalate privileges to admin user.
Issue is patched in 0.17.1, and fixed in 0.18.6+.
If Users are using 0.17.1, they should run "docker pull gravitl/netmaker:v0.17.1" and "docker-compose up -d". This will switch them to the patched users
If users are using v0.18.0-0.18.5, they should upgrade to v0.18.6 or later.
If using 0.17.1, can just pull the latest docker image of backend and restart server.
Credit to Project Discovery, and in particular https://github.com/rootxharsh , https://github.com/iamnoooob, and https://github.com/projectdiscovery
github.com/gravitl/netmaker < 0.17.1github.com/gravitl/netmaker >= 0.18.0, < 0.18.6Upgrade to a patched release:
github.com/gravitl/netmaker 0.17.1github.com/gravitl/netmaker 0.18.6Connected by shared product, vendor, weakness, or advisory.