CVE-2022-34770

Tabit - sensitive information disclosure

Description

Tabit - sensitive information disclosure. Several APIs on the web system display, without authorization, sensitive information such as health statements, previous bills in a specific restaurant, alcohol consumption and smoking habits. Each of the described API’s, has in its URL one or more MongoDB ID which is not so simple to enumerate. However, they each receive a ‘tiny URL’ in Tabit’s domain, in the form of https://tbit.be/{suffix} with suffix being a 5 characters long string containing numbers, lower- and upper-case letters. It is not so simple to enumerate them all, but really easy to find some that work and lead to a personal endpoint. This is both an example of OWASP: API4 - rate limiting and OWASP: API1 - Broken object level authorization. Furthermore, the redirect URL disclosed the MongoDB IDs discussed above, and we could use them to query other endpoints disclosing more personal information. For example: The URL https://tabitisrael.co.il/online-reservations/health-statement?orgId={org_id}&healthStatementId={health_statement_id} is used to invite friends to fill a health statement before attending the restaurant. We can use the health_statement_id to access the https://tgm-api.tabit.cloud/health-statement/{health_statement_id} API which disclose medical information as well as id number.

Remediation

Solution:

  • Update to version 3.27.0.

Category

4.6
CVSS
Severity: Medium
CVSS 3.1 •
EPSS 0.06%
Third-Party Advisory gov.il
Affected: Tabit Tabit
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2022-34770?
CVE-2022-34770 has been scored as a medium severity vulnerability.
How to fix CVE-2022-34770?
To fix CVE-2022-34770: Update to version 3.27.0.
Is CVE-2022-34770 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2022-34770 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2022-34770?
CVE-2022-34770 affects Tabit Tabit.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.