CVE-2024-55954
CVSS 3.1 Score 8.7 of 10 (high)
Details
Summary
CVE-2024-55954 is a vulnerability affecting OpenObserve's user management endpoint. This cloud-native observability platform contains a privilege escalation issue, where an "Admin" role user can remove a "Root" user from the organization. The "remove_user_from_org" function fails to enforce proper role checks, allowing the violation of intended privilege hierarchies. As a consequence, a non-root user, with "Admin" privileges, can eliminate the highest-privileged accounts. This vulnerability exposes potential full control to an attacker. The affected endpoint is `DELETE /api/{org_id}/users/{email_id}`. Users are advised to upgrade to release version `0.14.1` to address this issue, and there are no known workarounds.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.