Impact
NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The nl.nl-portal:documenten-api package through version 3.0.0 and the nl.nl-portal:besluiten package from version 1.5.0 through 3.0.0 lack per-user authorization in GraphQL resolvers, allowing an authenticated user to access other users’ document contents, decisions, audit trails, and decision attachments. Version 3.0.1 contains a patch. As a workaround, block the affected document-content and decision-related GraphQL operations at the API gateway or block their GraphQL types entirely.
Affected Systems
The vulnerability affects the nl.nl-portal:documenten-api package up to and including version 3.0.0 and the nl.nl-portal:besluiten package from version 1.5.0 through 3.0.0. Both packages are used in Dutch government portals that handle residents, customers, suppliers, and partner organizations. Version 3.0.1 of each package contains the necessary patch.
Risk and Exploitability
The CVSS score is 6.5, indicating a moderate severity. The EPSS score is < 1%, indicating a very low exploitation probability, but the flaw can be leveraged by any authenticated user who has valid credentials. It is not listed in the CISA KEV catalog, and the vulnerability does not require remote code execution or elevated privileges. The attackers do not need special prerequisites beyond legitimate authentication credentials.
OpenCVE Enrichment
Github GHSA