Description
Capgo before 12.128.2 contains a scope escalation vulnerability in the POST /functions/v1/apikey endpoint that allows app-limited API keys to mint unrestricted keys by setting empty limits. Attackers with a compromised app-limited key can create an unrestricted key with org-wide access to resources like app listings and other protected endpoints.
Problem types
Product status
Any version before 12.128.2
12.128.2 (semver)
Credits
Judel777
References
github.com/.../capgo/security/advisories/GHSA-2ff8-7h96-hwfp (GHSA Advisory GHSA-2ff8-7h96-hwfp)
www.vulncheck.com/...api-key-creation-in-functions-v1-apikey (VulnCheck Advisory: Capgo - Scope Escalation via API Key Creation in /functions/v1/apikey)