HIGHGo →
Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification
Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification
Affected packages
- github.com/identrail/identrail
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/identrail/identrail/security/advisories/GHSA-cp3j-m783-3ph5
- https://github.com/identrail/identrail/commit/835e40517509d6ef5405c27fbf14f579bedff0e7
- https://github.com/identrail/identrail
- https://github.com/identrail/identrail/releases/tag/v1.0.2
Structured record: https://osv.dev/vulnerability/GHSA-cp3j-m783-3ph5
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta