LubeLogger: IDOR in DuplicateRecordsToOtherVehicles Allows Copying Records from Any User's Vehicle Without Ownership Check
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.1epss 0.4%
exploitation probability
0.4%top 70% of all CVEs
observed exploitation
nono source reports it
LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, an authenticated user could submit caller-controlled recordIds to the DuplicateRecordsToOtherVehicles endpoint while naming destination vehicleIds the user could edit. The endpoint authorized the destination vehicles but fetched source records in Controllers/VehicleController.cs without checking UserCanEditVehicle for each existingRecord.VehicleId. This missing source-vehicle authorization allowed service, collision, upgrade, fuel, tax, supply, note, odometer, reminder, plan, inspection, and equipment records belonging to another user to be copied into an attacker-controlled vehicle, exposing record contents and attachment paths and creating persistent copies. This issue is fixed in version 1.6.8.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Affected products
hargata · lubelogReferences
https://github.com/hargata/lubelog/commit/c8d5888ebc69e6a163e33f36200233ec845e5c57https://github.com/hargata/lubelog/issues/1398https://github.com/hargata/lubelog/pull/1395https://github.com/hargata/lubelog/releases/tag/v1.6.8https://github.com/hargata/lubelog/security/advisories/GHSA-3r34-mx83-q67r