Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Grav 1.0.6 through 1.0.11 Privilege Escalation via Scoped API Keys
Vulnerability Description
The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege escalation vulnerability. A scoped API key minted on a super-admin account bypasses its declared scope cap on four isSuperAdmin()-gated write endpoints (in GroupsController, AccountsConfigController, PreferencesController, and DashboardWidgetController). These endpoints authorize via a super-admin early-return that never invokes requirePermission()—the sole enforcement point of the scope cap—so a 'read-only'-scoped key (e.g. api.pages.read) can perform super-only write operations, including rewriting group ACL maps to grant super-admin privileges to arbitrary accounts. A leaked or delegated read-only CI/monitoring key can therefore gain full super-admin write capability. Fixed in 1.0.13.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
特权管理不恰当
Vulnerability Title
Grav 权限许可和访问控制问题漏洞
Vulnerability Description
Grav是Grav组织开源的一款基于文件的扁平化内容管理系统。 Grav 1.0.6至1.0.11版本存在权限许可和访问控制问题漏洞,该漏洞源于部分端点通过超级管理员早退机制授权,未调用requirePermission()进行权限校验,导致受限API密钥绕过其声明的范围限制,从而可以执行超级管理员写操作,包括重写组ACL映射以授予任意账户超级管理员权限。
CVSS Information
N/A
Vulnerability Type
N/A