Advisories

BlueWave Checkmate <= 2.0.2 Invite Request Privilege Escalation

Go Back
severity
critical
date
Affecting
  • Checkmate <= 2.0.2 prior to commit d4a6072

CWE
  • CWE-863 Incorrect Authorization
CVSS
9.2
CVSS V4 Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Credit
Maksim Rogov
Description
BlueWave Checkmate versions up to and including 2.0.2, prior to commit d4a6072, contain a privilege escalation vulnerability in the invitation-based registration flow. A user can modify the invite/registration request body to supply attacker-controlled role and teamId values instead of having these attributes derived from the invitation token, allowing the creation of an account with elevated permissions (e.g., administrative roles) outside the intended authorization model.