Capgo
- < 12.128.2
An authorization vulnerability has been identified in Capgo versions prior to 12.128.2, specifically within the transfer_app() function. This flaw arises because the function fails to update the deploy_history.owner_org when applications are transferred between organizations. As a result, unauthorized access to deployment history records can be retained in the source organization, or the destination organization may lose access to the deployment records of transferred applications.
Exploitation of this vulnerability allows for cross-organization authorization issues and data integrity problems. The old organization may retain access to deployment history for applications no longer owned, while the new organization could lose access to important historical deployment records. This flaw disrupts the expected organizational boundaries in authorization for transferred applications and can create inconsistencies in the deployment history visibility and audit trail within the application's dashboard.
To reproduce this vulnerability, first create an application in the source organization. After the application is established, a deployment history record must be created by updating a channel version, which triggers the recording of deployment history. Once the deployment history is logged, the application can be transferred to the destination organization using the transfer_app() function. After the transfer, the application's ownership will reflect the new organization, but the deployment history will still be associated with the old organization, demonstrating the failure to update the deploy_history.owner_org as intended.
Users can update to Capgo version 12.128.2 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.