OliveTin EventStream Unauthorized Output Disclosure Vulnerability

Vulnerability

A vulnerability in OliveTin versions through 3000.10.2 allows low-privileged authenticated users to access unauthorized output from shell commands executed by other users. This issue arises because the application’s live EventStream broadcasts execution results and action outputs to all authenticated dashboard subscribers without proper authorization checks. As a result, sensitive information may be inadvertently disclosed, leading to broken access control.

Impact

Exploitation of this vulnerability allows low-privileged authenticated users to receive unauthorized execution output from privileged actions, including sensitive information such as secrets or internal system details. This bypasses intended access controls and could lead to unauthorized disclosure of operationally sensitive data.

Reproduction

The vulnerability can be reproduced by subscribing to the EventStream as a low-privileged authenticated user. Once subscribed, the EventStream will broadcast execution events and output from actions that the user is not authorized to view. This can be validated by executing a protected action that outputs sensitive information, such as a secret, and observing that the unauthorized user still receives the output through the EventStream.

Added: Mar 11, 2026, 9:28 PM
Updated: Mar 11, 2026, 9:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.3
remediation
0.0
relevance
3.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.