Hall of Fame image from https://openclipart.org/detail/120343/trophy
Back to Hall of Fame Contents Back to Wekan Website

Contents / AdminBleed

CVE Vulnerability name Date Responsible Security Disclosure by Vulnerabilities
TODO AdminBleed

2023-04-24 16.40 EET Christian Pöschl of usd AG Responsible Disclosure Team

Sent report.
  • Security: Non-Admin could change to Admin
  • Affected Wekan v6.85 and earlier
  • Fixed at Wekan v6.86 2023-04-26


Timeline Details
2023-04-24 16.40 EET Report received.

## usd-2023-0008 | WeKan 6.85.0 - Broken Access Control

### Details
**Advisory ID**: usd-2023-0008    
**Product**: WeKan     
**Affected Version**: <=6.85   
**Vulnerability Type**: Broken Access Control (CWE-284)   
**Security Risk**: High (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)   
**Vendor URL**: https://github.com/wekan/wekan    
**Vendor acknowledged vulnerability**: Yes / No    
**Vendor Status**: Not fixed / Fixed    
**Advisory Status**: Open/Published    
**CVE number**: Not requested yet    
**CVE Link**: Not requested yet    
**First Published**: Not published yet   
**Last Update**: 2023-04-24   

### Description
Wekan is a free and open-source collaborative Kanban board application that enables users to visualize their workflow and manage tasks.
It is built with the Meteor JavaScript framework and is designed to be easy to use.

A vulnerability in *WeKan* allows any user to escalate their privileges to admin user.

### Proof of Concept
(Waiting for every WeKan user at all platforms to upgrade)

### Timeline
* **2023-04-24**: First contact request via mail

### Credits
This security vulnerability was identified by Christian Pöschl of usd AG.

### About usd Security Advisories
In order to protect businesses against hackers and criminals, we always have to keep our skills and knowledge up to date.
Thus, security research is just as important for our work as is building up a security community to promote the exchange of knowledge.
After all, more security can only be achieved if many individuals take on the task.

Our CST Academy and our usd HeroLab are essential parts of our security mission.
We share the knowledge we gain in our practical work and our research through training courses and publications. 
In this context, the usd HeroLab publishes a series of papers on new vulnerabilities and current security issues. 

Always for the sake of our mission: "more security."

https://www.usd.de

### Disclaimer
The information provided in this security advisory is provided "as is" and without warranty of any kind.
Details of this security advisory may be updated in order to provide as accurate information as possible.
2023-04-26 23:30 EET
  • Security: Non-Admin could change to Admin
  • Affected Wekan v6.85 and earlier
  • Fixed at Wekan v6.86 2023-04-26


Back to Hall of Fame Contents Back to Wekan Website