CVE-2024-55954

CVSS 3.1 Score 8.7 of 10 (high)

Details

Published Jan 16, 2025
CWE ID 272
CWE ID 285
CWE ID 284
CWE ID 269
CWE ID 287

Summary

CVE-2024-55954 is a vulnerability affecting OpenObserve's user management endpoint. This cloud-native observability platform contains a privilege escalation issue, where an "Admin" role user can remove a "Root" user from the organization. The "remove_user_from_org" function fails to enforce proper role checks, allowing the violation of intended privilege hierarchies. As a consequence, a non-root user, with "Admin" privileges, can eliminate the highest-privileged accounts. This vulnerability exposes potential full control to an attacker. The affected endpoint is `DELETE /api/{org_id}/users/{email_id}`. Users are advised to upgrade to release version `0.14.1` to address this issue, and there are no known workarounds.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share