Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in the ToolJet low-code platform allows authenticated users to access, modify, or delete data belonging to other organizations. This could lead to data corruption or loss by bypassing security checks in the database endpoints.
- Users can alter or delete data across organizations.
- Confirms cross-tenant data access risks.
- Assess ToolJet use and data exposure.
Attack Path
How an attacker could exploit the issue
An attacker with Builder access can exploit this vulnerability by first discovering a victim organization's ID from public application endpoints. They can then use this ID to access specific database endpoints, allowing them to manipulate or delete tables within that organization's data, even without explicit authorization.
- Requires authenticated Builder user access.
- Triggered by manipulating organization ID in database endpoints.
- Risk of data corruption or destruction across tenants.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, authenticated users could manipulate database tables across different organizations within ToolJet. This may affect table schemas, lead to data corruption, or result in permanent data destruction.
- Data or system asset at risk: Tenant organization data and schemas.
- How exposure could happen: Exploiting path parameter flaws in database endpoints.
- Realistic consequence: Permanent data loss or corruption.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability in ToolJet affects its database management endpoints, allowing authenticated users to access or modify data across different organizations. This indicates a potential issue for platform teams managing the ToolJet deployment and application owners who rely on its data integrity. The first practical step is to identify all ToolJet instances, confirm their reachability and criticality, identify the accountable owners, and then prioritize remediation based on risk.
- Platform and application owners should lead remediation.
- Verify affected ToolJet instances and their reachability.
- Plan maintenance for data integrity and access controls.