QID 995642
Date Published: 2023-10-25
QID 995642: NodeJs (Npm) Security Update for xo-server (GHSA-grvm-gcqf-gh8q)
Xen Orchestra (with xo-web through 5.80.0 and xo-server through 5.84.0) mishandles authorization, as demonstrated by modified WebSocket resourceSet.getAll data is which the attacker changes the permission field from none to admin. The attacker gains access to data sets such as VMs, Backups, Audit, Users, and Groups.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-grvm-gcqf-gh8q for updates and patch information.
Vendor References
- GHSA-grvm-gcqf-gh8q -
github.com/advisories/GHSA-grvm-gcqf-gh8q
CVEs related to QID 995642
Software Advisories
| Advisory ID | Software | Component | Link |
|---|