Skip to content

Privilege escalation by backend users assigned to the default "Publisher" system role

Low severity GitHub Reviewed Published Nov 22, 2020 in octobercms/october • Updated Feb 1, 2023

Package

composer october/backend (Composer)

Affected versions

>= 1.0.319, < 1.0.470

Patched versions

1.0.470

Description

Impact

Backend users with the default "Publisher" system role have access to create & manage users where they can choose which role the new user has. This means that a user with "Publisher" access has the ability to escalate their access to "Developer" access.

Patches

Issue has been patched in Build 470 (v1.0.470) & v1.1.1.

Workarounds

Apply octobercms/october@78a3729 to your installation manually if unable to upgrade to Build 470 or v1.1.1.

References

Reported by Hoan Hoang

For more information

If you have any questions or comments about this advisory:

Threat assessment:

Screen Shot 2020-10-10 at 1 37 25 PM

### References - https://github.com/octobercms/october/security/advisories/GHSA-rfjc-xrmf-5vvw - https://github.com/octobercms/october/commit/4c650bb775ab849e48202a4923bac93bd74f9982 - https://nvd.nist.gov/vuln/detail/CVE-2020-15248 - https://github.com/octobercms/october/commit/78a37298a4ed4602b383522344a31e311402d829
@LukeTowers LukeTowers published to octobercms/october Nov 22, 2020
Reviewed Nov 23, 2020
Published to the GitHub Advisory Database Nov 23, 2020
Published by the National Vulnerability Database Nov 23, 2020
Last updated Feb 1, 2023

Severity

Low

EPSS score

0.044%
(14th percentile)

CVE ID

CVE-2020-15248

GHSA ID

GHSA-rfjc-xrmf-5vvw

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.