Impact
The reported flaw lies in the update method of the UserSerializer class in the backend/rbac/serializers.py module of SxDevOps 1.0 and 1.1. The code incorrectly handles privilege assignments, allowing an attacker to manipulate user roles or permission levels beyond their intended scope. This flaw results in improper privilege management, effectively enabling a privileged escalation that could expose sensitive data or compromise system integrity.
Affected Systems
SxDevOps, an open-source DevOps platform maintained by aiyiyi121, is affected by versions 1.0 and 1.1.
Risk and Exploitability
The CVSS severity is 5.1, indicating a medium risk that does not include denial of service or remote code execution but still requires immediate attention. Because the EPSS score is not available and the vulnerability is not listed in CISA KEV, the likelihood of exploitation remains uncertain; however, the remote attack capability makes it a typical target for adversaries seeking to increase privileges. The lack of a CVSS vector for attack complexity or privileges suggests that exploitation may not require advanced skills, further elevating the risk profile for unpatched deployments.
OpenCVE Enrichment