Description
Capgo before 12.128.2 contains an improper access control vulnerability in the public.get_org_members RPC function that allows unauthenticated attackers to enumerate organization members. Attackers can invoke the endpoint using only the public sb_publishable_* key and an organization UUID to retrieve sensitive member information including email addresses, user IDs, roles, and pending invitations.
Problem types
Product status
Any version before 12.128.2
12.128.2 (semver)
Credits
Judel777
References
github.com/.../capgo/security/advisories/GHSA-x34h-gc65-f6g4
github.com/.../capgo/security/advisories/GHSA-x34h-gc65-f6g4 (GHSA Advisory GHSA-x34h-gc65-f6g4)
www.vulncheck.com/...mail-disclosure-via-get-org-members-rpc (VulnCheck Advisory: Capgo - Unauthenticated Organization Member Email Disclosure via get_org_members RPC)