Description
ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If the user opens the invite link/signup link and then clicks on any external links within the page, it leaks the password set token/signup token in the referer header. Using these tokens the attacker can access the user’s account.
No analysis available yet.
Remediation
Vendor Solution
Update to version v1.3.0 or later
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-28174 | ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If the user opens the invite link/signup link and then clicks on any external links within the page, it leaks the password set token/signup token in the referer header. Using these tokens the attacker can access the user’s account. |
References
History
No history.
Status: PUBLISHED
Assigner: Mend
Published:
Updated: 2024-09-16T18:13:10.998Z
Reserved: 2022-01-10T00:00:00.000Z
Link: CVE-2022-23067
No data.
Status : Modified
Published: 2022-05-18T14:15:08.353
Modified: 2024-11-21T06:47:55.207
Link: CVE-2022-23067
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD