Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability impacts BookStack, a documentation and wiki platform, by allowing unauthorized access through its social login feature. Attackers can bypass authentication by exploiting how the system handles different social login providers. The main concern is confirming if your BookStack instances are using this specific social login functionality and are therefore exposed.
- Bypasses login by confusing social providers.
- Leadership should understand its reach.
- Confirm if social login is in use.
Attack Path
How an attacker could exploit the issue
An attacker could bypass authentication by exploiting how BookStack handles social logins. By using a specific user ID with one social login provider, an attacker could trick the system into logging them in as a different user linked to another social provider. This occurs because the system doesn't properly check which social provider is being used when linking accounts.
- Attacker needs network access.
- Triggered by logging in via social media.
- Risk of unauthorized account access.
Live Threat
Current exploitation, exposure, and threat context
Unauthenticated attackers could bypass login and impersonate any user on a BookStack instance when social login is enabled and configured in a specific way. This could occur if an attacker uses a user ID associated with one social login provider to authenticate through a different provider that shares the same driver ID namespace, effectively tricking the system into granting access.
- User accounts and access.
- Attacker authenticates with a different provider.
- Unauthorized access to user data.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability affects BookStack's social login functionality, making it a concern for teams responsible for the application and its user authentication. The first step is to identify all BookStack instances, determine their exposure and business criticality, and locate the specific team or individual accountable for managing user authentication.
- Application owners responsible for BookStack.
- Verify social login reachability and criticality.
- Plan remediation based on exposure and criticality.