Impact
A flaw exists in the NoOp RBAC backend used by StackStorm st2, specifically within the function assert_user_is_admin_if_user_query_param_is_provided in actionexecutions.py. The function improperly handles the User argument, allowing an attacker to acquire administrative privileges by manipulating user parameters. This privilege escalation can be achieved remotely as the exploit is available to the public.
Affected Systems
The vulnerability affects all installations of StackStorm st2 up to version 3.9.0, regardless of whether RBAC is enabled. The affected component is the NoOp RBAC backend. Any user or service that can exploit the API endpoint of the action executions controller is susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, since the attack vector is remote and the exploit is publicly available, the risk of privilege escalation remains significant. An attacker could gain admin rights to the StackStorm controller, potentially compromising the orchestrated workflows and data stored within the system.
OpenCVE Enrichment