Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in the OpenCTI platform, a tool for managing cyber threat intelligence, could allow an unauthorized user to delete entire workspaces, including dashboards and investigation cases. This issue affects versions prior to 6.8.1 and stems from a lack of proper authorization checks when deleting workspace-related objects.
- Unauthorized deletion of user workspaces.
- Critical for maintaining data integrity.
- Confirm relevance and exposure.
Attack Path
How an attacker could exploit the issue
An attacker can exploit this vulnerability by sending a request to the GraphQL API that targets a workspace belonging to another user. Without proper validation, the system will allow the deletion of the targeted workspace's objects, leading to the loss of critical threat intelligence data.
- An attacker needs network access to the API.
- The attacker must know another user's workspace UUID.
- Risk includes unauthorized data deletion.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, an attacker could exploit this vulnerability by deleting entire workspaces, including dashboards and investigation cases, which are critical components of threat intelligence management. This occurs when the GraphQL mutation fails to perform adequate authorization checks, allowing unauthorized users to delete resources they do not own.
- Workspace data and investigation cases.
- Unauthorized deletion via API call.
- Loss of critical threat intelligence.
Operational Fix
Recommended remediation, mitigation, and detection steps
The OpenCTI platform, used for managing cyber threat intelligence, is vulnerable to unauthorized deletion of workspace data via its GraphQL API. This critical vulnerability could allow any unauthenticated attacker to delete dashboards and investigation cases by exploiting a lack of ownership checks. Immediate action is required to identify affected instances, assess their business criticality and network exposure, and determine the accountable owner for remediation.
- Platform owners should manage the issue.
- Verify all OpenCTI instances for exposure.
- Plan and execute the upgrade to version 6.8.1.