d4software / QueryTree

Data reporting and visualization for your app
http://querytreeapp.com
GNU Lesser General Public License v3.0
341 stars 122 forks source link

Security vulnerability in versions prior to 3.0.99 (CVE-2019-19249) #90

Closed d4nt closed 4 years ago

d4nt commented 4 years ago

There exists a vulnerability in QueryTree allowing any user to join any arbitrary organization. This allows an unauthenticated attacker to gain complete access to any QueryTree organization simply by registering an account.

Thanks to @cablej for reporting this issue.

A CVE has been raised for this issue here: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19249

This issue is fixed by 57b700823f8eb1a42eb3bc0c706fbe5e5f5e766f

Suggested Remediation:

Upgrade to 3.0.99 or later.