Impact
When the V3 Locations feature is enabled, which is the default, an authenticated user with membership on a single product could obtain standing over endpoint records belonging to other products, and then modify or remove records that those other products rely on. No administrator access was required.
Reading the shared labels on such a record is a separate issue, tracked in GHSA-rr5c-4hrj-f5wp.
Patches
Resolved by scoping endpoint modification and removal to the requesting product's own references, and by authorizing the object named in each request rather than only the record it hangs from. Upgrade to 3.2.300 (Open Source and Pro).
Workarounds
No complete workaround; upgrade to 3.2.300.
References
The Pro fix ships in Pro 3.2.300.
We thank riodrwn for the responsible disclosure and assistance.
Impact
When the V3 Locations feature is enabled, which is the default, an authenticated user with membership on a single product could obtain standing over endpoint records belonging to other products, and then modify or remove records that those other products rely on. No administrator access was required.
Reading the shared labels on such a record is a separate issue, tracked in GHSA-rr5c-4hrj-f5wp.
Patches
Resolved by scoping endpoint modification and removal to the requesting product's own references, and by authorizing the object named in each request rather than only the record it hangs from. Upgrade to 3.2.300 (Open Source and Pro).
Workarounds
No complete workaround; upgrade to 3.2.300.
References
The Pro fix ships in Pro 3.2.300.
We thank riodrwn for the responsible disclosure and assistance.