5.3
CVSSv3

CVE-2018-20345

Published: 21/12/2018 Updated: 24/08/2020
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.3 | Impact Score: 3.6 | Exploitability Score: 1.6
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N

Vulnerability Summary

Incorrect access control in StackStorm API (st2api) in StackStorm prior to 2.9.2 and 2.10.x prior to 2.10.1 allows an attacker (who has a StackStorm account and is authenticated against the StackStorm API) to retrieve datastore items for other users by utilizing the /v1/keys "?scope=all" and "?user=<username>" query filter parameters. Enterprise editions with RBAC enabled are not affected.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

stackstorm stackstorm