Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability affects CordysCRM, an open-source customer relationship management system. It allows unauthenticated access to sensitive user information and the ability to inject or terminate user data streams. The main concern is confirming relevance and exposure.
- Access to user data without login.
- Sensitive workflow and alert information exposed.
- Confirm if CordysCRM is used.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can interact with CordysCRM's Server-Sent Events (SSE) endpoints. By sending requests to `/sse/subscribe`, `/sse/broadcast`, or `/sse/close`, an attacker can potentially view other users' sensitive workflow data, inject messages into their streams, or terminate their connections. This is possible because the system trusts user-provided identifiers instead of verifying authenticated user sessions.
- Accessible over the network without authentication.
- Triggered by sending requests to SSE endpoints.
- Allows unauthorized access to user data.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an unauthenticated user to access another user's workflow events, approval requests, mentions, and alerts within the CordysCRM system. It also enables the injection of system messages into another user's data stream and the termination of their communication channel.
- User-specific sensitive information.
- Unauthenticated access to user data.
- Unauthorized access and disruption.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability in CordysCRM impacts organizations using private deployments of the system. The platform team or the application owners are likely responsible for addressing this issue, as it affects the core functionality of the CRM. The first practical step is to identify all instances of CordysCRM, confirm their reachability and business criticality, and then coordinate remediation efforts.
- Identify affected deployments and owners.
- Verify external reachability and impact.
- Plan and execute updates or vendor coordination.