Summary
This vulnerability allows an authenticated malicious actor to modify the user profile information of another account without requiring elevated privileges by manipulating the user ID in the profile update request.
Patches
This vulnerability was addressed in DefectDojo Pro 2.49.1-1
Workarounds
Upgrade to DefectDojo Pro 2.49.1-1
Impact
For users created via SSO, the impact is limited to a potential denial of service through the "force password reset" user profile setting. For local user accounts that do not have MFA enabled, exploiting this flaw in a two step process can lead to account takeover. First an authenticated malicious actor would abuse the flaw to update the email address for a local user account, and then utilize the password reset function to gain access to an account.
Credits
Aadesh Jain (@ajcybertron)
Summary
This vulnerability allows an authenticated malicious actor to modify the user profile information of another account without requiring elevated privileges by manipulating the user ID in the profile update request.
Patches
This vulnerability was addressed in DefectDojo Pro 2.49.1-1
Workarounds
Upgrade to DefectDojo Pro 2.49.1-1
Impact
For users created via SSO, the impact is limited to a potential denial of service through the "force password reset" user profile setting. For local user accounts that do not have MFA enabled, exploiting this flaw in a two step process can lead to account takeover. First an authenticated malicious actor would abuse the flaw to update the email address for a local user account, and then utilize the password reset function to gain access to an account.
Credits
Aadesh Jain (@ajcybertron)