CVE-2022-36110: high-severity vulnerability in gravitl netmaker
Netmaker vulnerable to Insufficient Granularity of Access Control
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
Netmaker allowed non-admin users to perform administrator-level actions through the API by using their authentication tokens. This means someone without admin permission could gain full control over the network configuration and other sensitive operations.
Netmaker prior to v0.15.1 suffers from improper authorization in API endpoints, allowing authenticated non-privileged users to execute administrator-level functions. The vulnerability stems from insufficient access control granularity (CWE-1220, CWE-285), where API authorization checks fail to properly verify user privileges before executing sensitive operations, resulting in privilege escalation.
In the same product, most dangerous first.