Description
OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows unauthenticated attackers to gain ROOT privileges when the root_api_key configuration is omitted. Attackers can send requests to protected endpoints without authentication headers to access administrative functions including account management, resource operations, and system configuration.
Problem types
CWE-306 Missing Authentication for Critical Function
Product status
Any version
commit 0251c70
Credits
Chia Min Jun Lennon
References
github.com/volcengine/OpenViking/issues/302
github.com/volcengine/OpenViking/pull/310
github.com/...anges/0251c7045b3f8092c4d2e1565115b1ba23db282f
www.vulncheck.com/...ot-api-key-allows-anonymous-root-access