CVE-2023-32749: High severity pydio vulnerability
Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying the HTTP request sent when creating such an external user, it is possible to assign the new user arbitrary roles. By assigning all roles to a newly created user, access to all cells and non-personal workspaces is granted.
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-32749?
CVE-2023-32749 is classified as a high severity vulnerability due to potential privilege escalation.
How do I fix CVE-2023-32749?
To fix CVE-2023-32749, upgrade Pydio Cells to version 4.1.3 or later.
What is the impact of CVE-2023-32749?
CVE-2023-32749 allows unauthorized users to gain excessive access to files by creating external users with arbitrary roles.
Which versions of Pydio Cells are affected by CVE-2023-32749?
CVE-2023-32749 affects Pydio Cells versions prior to 4.1.0 and 3.0.12.
Who is vulnerable to CVE-2023-32749?
Organizations using versions of Pydio Cells below 4.1.3 are vulnerable to CVE-2023-32749.