CVE-2024-1314High· 8.6▾ TwilightKinto Attachment's attachments can be replaced on read-only records
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
The attachment file of an existing record can be replaced if the user has "read" permission on one of the parent (collection or bucket).
And if the "read" permission is given to "system.Everyone" on one of the parent, then the attachment can be replaced on a record using an anonymous request.
Note that if the parent has no explicit read permission, then the records attachments are safe.
None if the read permission has to remain granted.
Updating to 6.4.0 or applying the patch individually (if updating is not feasible) is strongly recommended.
kinto-attachment < 6.4.0Upgrade to a patched release:
kinto-attachment 6.4.0