Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
@better-auth/stripe before 1.6.21 Authorization Bypass via Organization Subscription
Vulnerability Description
@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organization subscription actions. The middleware validates the organization ID taken from the request query string against the authorizeReference callback, but the handler reads the organization ID only from the request body and falls back to the caller's active organization from their session. When these differ, an authenticated member of multiple organizations can perform subscription actions (cancel, change plan, restore, billing portal access) against an organization they belong to but should not manage, and can access another organization's billing details including payment methods, invoices, and subscription state.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
better-auth stripe 授权问题漏洞
Vulnerability Description
better-auth stripe是better-auth团队开源的一款在线支付处理平台。 better-auth stripe 1.4.11版本至1.6.21之前版本和1.7.0-beta.0版本至1.7.0-beta.10之前版本存在授权问题漏洞,该漏洞源于对组织ID验证不当,导致授权绕过,可能使已认证的多组织成员对其所属但无权管理的组织执行订阅操作,并访问其他组织的账单详情。
CVSS Information
N/A
Vulnerability Type
N/A