Federated share permissions can be increased by recipient

Disclosed: 2023-06-24 08:28:41 By rullzer To owncloud
Medium
Vulnerability Details
1. userA on serverX does a federated share to userB on serverY (this by default is read only) 2. userB accepts the share 3. userB does a request to ```https://SERVERY/apps/federatedfilesharing/notifications``` With the content. Replacing the SHARE_TOKEN, and the SHARE_ID they find in their database ``` { "notificationType": "RESHARE_CHANGE_PERMISSION", "resourceType": "file", "providerId": "SHARE_ID", "notification": { "sharedSecret": "SHARE_TOKEN", "permission": ["read", "write", "share"] } } ``` 4. userB now has full access ## Impact A recipient can increase their permissions trivially
Actions
View on HackerOne
Report Stats
  • Report ID: 1990443
  • State: Closed
  • Substate: resolved
  • Upvotes: 27
Share this report