Summary
Presigned S3 URL in upload Avatar feature returned for victim's asset with no authentication.
Details
plane/app/views/asset/v2.py:452 — permission_classes = [AllowAny]
Issue is here:
GET /api/assets/v2/static/beb4da02-b0ee-4d2a-9258-4768c5c5c933/
the request has zero cookies, zero auth header for this request
PoC
Login to the application and upload Avatar ( image).
Copy link to this image and open it in a different browser.
The url reveals X-Amz-Credential=access-key, X-Amz-Signature, X-Amz-Expires without proper authorisation.
Impact
Anyone on the internet, can access any asset UUID. No account needed at all.
Summary
Presigned S3 URL in upload Avatar feature returned for victim's asset with no authentication.
Details
plane/app/views/asset/v2.py:452 — permission_classes = [AllowAny]
Issue is here:
GET /api/assets/v2/static/beb4da02-b0ee-4d2a-9258-4768c5c5c933/
the request has zero cookies, zero auth header for this request
PoC
Login to the application and upload Avatar ( image).
Copy link to this image and open it in a different browser.
The url reveals X-Amz-Credential=access-key, X-Amz-Signature, X-Amz-Expires without proper authorisation.
Impact
Anyone on the internet, can access any asset UUID. No account needed at all.