Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 have a critical Insecure Direct Object Reference (IDOR) issue which could allow unauthorized users to modify custom fields across boards through its custom fields update endpoints, potentially leading to unauthorized data manipulation. The PUT /api/boards/:boardId/custom-fields/:customFieldId endpoint in Wekan validates that the authenticated user has access to the specified boardId, but the subsequent database update uses only the custom field's _id as a filter without confirming the field actually belongs to that board. This means an attacker who owns any board can modify custom fields on any other board by supplying a foreign custom field ID, and the same flaw exists in the POST, PUT, and DELETE endpoints for dropdown items under custom fields. The required custom field IDs can be obtained by exporting a board (which only needs read access), since the exported JSON includes the IDs of all board components. The authorization check is performed against the wrong resource, allowing cross-board custom field manipulation. This issue has been fixed in version 8.34.
The PUT /api/boards/:boardId/custom-fields/:customFieldId endpoint verifies whether the user has access to the provided boardId, however the subsequent database update operation filters records only by custom field identifier (_id), without checking whether the field actually belongs to the indicated board. An attacker possessing their own board can therefore specify the custom field identifier from another board and modify it without permissions. The same flaw affects POST, PUT and DELETE endpoints for dropdown items associated with custom fields. Custom field identifiers from other boards can be obtained by exporting a board to which the attacker has read-only access, since the exported JSON file contains identifiers of all board components.
An attacker can unauthorized modify or delete custom fields and their values on any boards in a Wekan instance, leading to manipulation of project data of other users and teams.
Wekan should be updated to version 8.34, in which the manufacturer removed the described vulnerability. The patch is available in the project's GitHub repository (commit 73eb98c57afd3d72377a1f7160a52450ab0eeb8b) and as part of the v8.34 release.
Wekan Project Wekan in versions 8.32 and 8.33
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XWekan Project Wekan
APPWekan Project8.328.33
Related vulnerabilities
SSRF w Wekan — nieautoryzowany dostęp do wewnętrznych zasobów sieciowych
Wekan: ujawnienie wrażliwych danych użytkowników przez publikację notificationUsers
Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks pub...
WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and rela...
WeKan versions prior to 8.19 contain an authorization weakness in the attachment upload API. The API does not ...