Horizon Alert
Summary of the vulnerability and why it matters
A critical security vulnerability exists in Casdoor through version 4.4.0 that allows unauthorized access to user administration functions. If exploited, an attacker could gain broad control over user accounts across all organizations, including viewing sensitive information and creating or deleting administrators. The main concern is confirming relevance and exposure.
- Bypass allows unauthorized user administration.
- Critical vulnerability impacts identity management.
- Confirm relevance and exposure.
Attack Path
How an attacker could exploit the issue
An attacker can leverage an authorization bypass in the API to achieve unrestricted access to user administration across all organizations. This is possible by using a legitimate `clientId` and `clientSecret` from any application. The attacker can then enumerate user details, create new administrators, or modify and delete existing user accounts within any organization.
- Requires any application's credentials.
- Triggered by accessing the `/api/mcp` endpoint.
- Risk: Unrestricted user administration and data exposure.
Live Threat
Current exploitation, exposure, and threat context
The authorization bypass vulnerability in the /api/mcp endpoint could allow an attacker with valid application credentials to gain administrative control over user accounts across all organizations. This could lead to unauthorized modification, creation, or deletion of user data, including sensitive information such as password salts and email addresses.
- User account data.
- Unrestricted API access.
- Compromise of user administration.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability impacts Casdoor deployments, potentially affecting application owners, platform teams, and security operations. The first practical step is to identify all Casdoor instances, determine their network exposure and business criticality, and confirm the accountable owner for each. Subsequent remediation planning should be risk-based, considering factors like maintenance windows and potential vendor coordination.
- Identify affected Casdoor instances and owners.
- Verify network exposure and business criticality.
- Plan risk-based remediation and vendor engagement.