ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation. A Tenant Administrator can obtain System Administrator dashboard access by modifying the scope via the scopes parameter.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://thingsboard.io/docs/reference/releases/ | release notes |
https://exchange.xforce.ibmcloud.com/vulnerabilities/238543 | third party advisory vdb entry |