Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Support
  3. Security bug that allow unauthorized access

Security bug that allow unauthorized access

Scheduled Pinned Locked Moved Solved Support
securitypassword
7 Posts 5 Posters 1.0k Views 7 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M Offline
    M Offline
    mcgiwer
    wrote on last edited by girish
    #1

    I want to report a serious security bug that allow unauthorized access to someones else account.

    Description:

    The password change option generates a password change link, with doesn't verify neither the old password, nor the 2FA(if enabled) and allow to change the other user's password and then access that profile.

    luckowL 1 Reply Last reply
    0
    • nebulonN Offline
      nebulonN Offline
      nebulon
      Staff
      wrote on last edited by
      #2

      Are you referring to the password change UI as such in the profile page or the password reset in case a user forgot the password, which is sending that password change link to the user's email account?

      M 1 Reply Last reply
      0
      • M mcgiwer

        I want to report a serious security bug that allow unauthorized access to someones else account.

        Description:

        The password change option generates a password change link, with doesn't verify neither the old password, nor the 2FA(if enabled) and allow to change the other user's password and then access that profile.

        luckowL Offline
        luckowL Offline
        luckow
        translator
        wrote on last edited by
        #3

        @mcgiwer The right workflow is responsible disclosure. Please take a look at https://www.cloudron.io/security.html

        Pronouns: he/him | Primary language: German

        1 Reply Last reply
        3
        • nebulonN nebulon

          Are you referring to the password change UI as such in the profile page or the password reset in case a user forgot the password, which is sending that password change link to the user's email account?

          M Offline
          M Offline
          mcgiwer
          wrote on last edited by
          #4

          @nebulon I mean the place where all users are listed.

          There is a risk that the password change may become missused to gain unauthorized access to someone else account. All because the fact that the password change form doesn't ask for neither old password, or 2FA key (if it's enabled for the user).

          The best example of that is visible in the online demo

          jdaviescoatesJ girishG 2 Replies Last reply
          0
          • M mcgiwer

            @nebulon I mean the place where all users are listed.

            There is a risk that the password change may become missused to gain unauthorized access to someone else account. All because the fact that the password change form doesn't ask for neither old password, or 2FA key (if it's enabled for the user).

            The best example of that is visible in the online demo

            jdaviescoatesJ Offline
            jdaviescoatesJ Offline
            jdaviescoates
            wrote on last edited by
            #5

            @mcgiwer said in Security bug that allow unauthorized acceds:

            @nebulon I mean the place where all users are listed.

            Surely only Admins (who - on purpose - can very easily impersonate anyone anyway) are the only people who can access that page anyway? 🤷 🤔

            I use Cloudron with Gandi & Hetzner

            1 Reply Last reply
            1
            • M mcgiwer

              @nebulon I mean the place where all users are listed.

              There is a risk that the password change may become missused to gain unauthorized access to someone else account. All because the fact that the password change form doesn't ask for neither old password, or 2FA key (if it's enabled for the user).

              The best example of that is visible in the online demo

              girishG Offline
              girishG Offline
              girish
              Staff
              wrote on last edited by
              #6

              @mcgiwer said in Security bug that allow unauthorized acceds:

              All because the fact that the password change form doesn't ask for neither old password,

              It's meant to change the password presumably because you forgot the old password. So, it can't ask for the old password.

              or 2FA key (if it's enabled for the user).

              I can't reproduce this. If the user had 2FA setup, the password reset link requires 2FA. Can you tell me which version of Cloudron you are using? I am testing on 7.6.4.

              image.png

              1 Reply Last reply
              2
              • girishG Offline
                girishG Offline
                girish
                Staff
                wrote on last edited by girish
                #7

                On second thoughts, I will mark this issue as 'resolved' here. If you can send us a detailed report to security@cloudron.io , would be much appreciated.

                edit: i actually see that you already reported this there. Thanks, let's follow up there.

                1 Reply Last reply
                3
                • girishG girish marked this topic as a question on
                • girishG girish has marked this topic as solved on
                • girishG girish locked this topic on
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                • Login

                • Don't have an account? Register

                • Login or register to search.
                • First post
                  Last post
                0
                • Categories
                • Recent
                • Tags
                • Popular
                • Bookmarks
                • Search