Quark Drive Mass Assignment Vulnerability in POST /update Endpoint
Vulnerability
A mass assignment vulnerability has been identified in Quark Drive versions prior to 0.8.5. This vulnerability exists in the POST /update endpoint, where authenticated attackers can overwrite administrator credentials. By posting an arbitrary webui object to the config_data dictionary, attackers exploit inadequate deny-list filtering to permanently replace stored login credentials. This action can lock out legitimate administrators and provide persistent access to all configured tasks, cloud tokens, and notification services.
Impact
Exploitation of this vulnerability allows for unauthorized modification of administrator credentials, potentially locking out legitimate users and granting persistent access to sensitive tasks and services.
Remediation
Users can update to Quark Drive version 0.8.6 or later, where this vulnerability has been patched.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
