Conversation
POST /users/v1/register previously took an 'admin' boolean straight from the client-supplied JSON body and used it to set the new user's privilege level, letting any anonymous caller register themselves as an administrator. New accounts are now always created as non-admin regardless of any extra 'admin' (or other) field present in the request body.
🏆 VAmPI — CTF Patch Score1 / 9 challenges patched
Commit: 🎉 Your result is on the leaderboard — see where you rank! 🏆 |
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Vulnerability
POST /users/v1/registeraccepted a client-suppliedadminboolean in the JSON request body and used it directly when creating the new user, letting any anonymous caller self-register as an administrator (API6:2019 Mass Assignment).Fix
register_user()inapi_views/users.pyno longer reads any privilege field from client input. Every newly self-registered account is now created as non-admin, regardless of what extra fields (e.g.admin) are present in the request body.Verification (local, WSL, vulnerable=1)
GET /createdb.POST /users/v1/registerwith{"username":"evil_admin",...,"admin":true}-> registration succeeds (200) butGET /users/v1/_debugshows the new user with"admin": false— privilege escalation no longer possible.