Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Request to publish GHSA-24vc-w334-95wm in the GitHub Advisory Database

未关闭
#9,008 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
35/100
Issue 类型
文档
描述清晰度
基本清楚
活跃度
冷清

调研方向

结合 Homer release 11.0.309 和 pull request 920,审查现有的 GHSA-24vc-w334-95wm 上下文,然后按照 advisory-database 针对已公开披露漏洞的整理工作流进行处理。确认的问题完成审查,并发布包含受影响版本和已修复版本、严重性、影响及修复措施的适当公共 advisory 记录,即表示完成。

由索引模型根据 Issue 内容生成。

描述

Summary

Hello GitHub Security Advisory team,

I am the original reporter of GHSA-24vc-w334-95wm, an authenticated privilege-escalation vulnerability in sipcapture/homer.

I reported the issue through GitHub Private Vulnerability Reporting, provided a proof of concept, and verified the vulnerability. The maintainers confirmed the issue and released a fix in Homer 11.0.309.

The repository advisory was subsequently closed as resolved without public publication. Although the vulnerability and its fix are now mentioned publicly in the project release notes and pull request, there is no public advisory record describing the affected versions, severity, impact, and remediation.

I am therefore requesting that this vulnerability be reviewed for publication in the GitHub Advisory Database.

Vulnerability

An authenticated non-administrative user could update their own account through:

PATCH /api/v4/users/:id

The endpoint accepted privileged account fields, including user_group, allowing a low-privileged user to assign themselves the administrator role.

The issue resulted from a combination of incorrect authorization logic and improper modification of privileged object attributes.

The fix restricts modification of user_group and enabled to administrators while preserving ordinary self-service profile updates.

Version information

  • Confirmed affected version: 11.0.307
  • Fixed version: 11.0.309
  • Exact introduced version: unknown

Classification

  • CWE-863: Incorrect Authorization
  • CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes
  • Severity: High

Suggested CVSS 4.0 vector:

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Public references

Request

Could the GitHub Security Advisory curation team review this confirmed, publicly disclosed, and fixed vulnerability and publish an appropriate global advisory record, using the existing GHSA-24vc-w334-95wm identifier if possible?

A public advisory would ensure that users of affected Homer versions are clearly informed about the privilege-escalation risk and the need to upgrade to version 11.0.309 or later.

It would also provide structured vulnerability information for security researchers, vulnerability-management platforms, and security scanners that consume GitHub Advisory Database data.

Reporter attribution or public credit is not required. My goal is to ensure that users of affected versions are appropriately informed.

I can provide additional information from the original private report through an appropriate non-public channel if required.

主要语言
没有语言数据
星标
2.5k
派生
789
平均合并
5 天 22 小时
30 天内合并 PR
68

环境准备

  • 没有 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 阅读贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

github/advisory-database 的其他 Issue

查看 github/advisory-database 的全部 Issue

相似的 Issue

更多 Documentation Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。