Horizon Alert
Summary of the vulnerability and why it matters
This critical vulnerability affects Jet Admin, a platform used for building and managing applications, allowing an attacker to create a malicious app, redirect user traffic, and steal sensitive authentication credentials like OAuth Client IDs and Secrets. The main concern is confirming relevance and exposure.
- Malicious apps can steal user credentials.
- It impacts systems managing web applications.
- Confirm relevance and exposure for your systems.
Attack Path
How an attacker could exploit the issue
An attacker could leverage this vulnerability by creating a malicious application within Jet Admin and associating it with a target user's custom domain. This allows the attacker to alter authentication settings, redirecting traffic to their own controlled application. If the victim uses an OAuth provider, the attacker gains access to their OAuth Client ID and Client Secret.
- Accessible via a public network.
- Attacker manipulates app settings and custom domain.
- Leads to credential theft and traffic redirection.
Live Threat
Current exploitation, exposure, and threat context
An attacker could create a malicious app within Jet Admin, connect it to a target user's custom domain, and alter authentication settings to redirect traffic to their own app. This could expose sensitive OAuth credentials if the victim uses an OAuth provider.
- OAuth Client ID and Client Secret.
- Malicious app redirects user traffic.
- Unauthorized access to user accounts.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability in Jet Admin requires immediate attention from teams responsible for application security and internal tooling. The first step is to identify all instances of Jet Admin within your environment, assess their exposure, and determine business criticality. Subsequently, engage the accountable owners to plan and execute remediation, prioritizing instances that are externally accessible or handle sensitive data.
- Application or platform teams own remediation.
- Verify Jet Admin instances and exposure.
- Plan and coordinate risk-based fixes.