Description
In Elide before 4.5.14, it is possible for an adversary to "guess and check" the value of a model field they do not have access to assuming they can read at least one other field in the model. The adversary can construct filter expressions for an inaccessible field to filter a collection. The presence or absence of models in the returned collection can be used to reconstruct the value of the inaccessible field. Resolved in Elide 4.5.14 and greater.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-0323 | In Elide before 4.5.14, it is possible for an adversary to "guess and check" the value of a model field they do not have access to assuming they can read at least one other field in the model. The adversary can construct filter expressions for an inaccessible field to filter a collection. The presence or absence of models in the returned collection can be used to reconstruct the value of the inaccessible field. Resolved in Elide 4.5.14 and greater. |
Github GHSA |
GHSA-2mxr-89gf-rc4v | Read permissions not enforced for client provided filter expressions in Elide. |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T08:22:09.123Z
Reserved: 2020-01-02T00:00:00.000Z
Link: CVE-2020-5289
No data.
Status : Modified
Published: 2020-03-30T22:15:15.463
Modified: 2024-11-21T05:33:50.560
Link: CVE-2020-5289
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA