OSV 1.4.0 · github-reviewed · 修改于 2026-06-05 03:23
发布时间
2026-06-05 03:23
GitHub 审查时间
2026-06-05 03:23
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/06/GHSA-gv8p-48fr-4fxg/GHSA-gv8p-48fr-4fxg.json
A non-admin API user with integration:create ACL privilege can escalate to full administrator by creating an integration with admin: true through the Sync API (POST /api/_action/sync). The regular integration endpoint (POST /api/integration) correctly blocks this, but the Sync API bypasses the controller-level check by writing directly through the DAL EntityWriter. The integration entity definition lacks WriteProtection, and the admin field has no field-level restriction flag.
OWASP: A01:2021 — Broken Access Control
IntegrationController::upsertIntegration() checks $source->isAdmin() before allowing the admin field to be set. However, SyncController::sync() routes writes through SyncService → EntityWriter, which only applies:
AclWriteValidator — checks entity-level ACL (integration:create is sufficient)EntityProtectionValidator — checks WriteProtection on entity definitions, but IntegrationDefinition has noneThe admin field in IntegrationDefinition is a plain BoolField with no WriteProtection or special flag. The Sync API writes it without restriction.
Vulnerable code path:
src/Core/Framework/Api/Controller/SyncController.php → SyncService → EntityWriter::upsert()src/Core/Framework/Integration/IntegrationDefinition.php — admin field has no WriteProtection(Context::SYSTEM_SCOPE)Working protection (bypassed):
src/Core/Framework/Integration/IntegrationController.php:46-56 — isAdmin() check only applies to the dedicated controller endpointAdd WriteProtection(Context::SYSTEM_SCOPE) to IntegrationDefinition, matching how UserDefinition and AclRoleDefinition are already protected:
// src/Core/Framework/Integration/IntegrationDefinition.php
(new BoolField('admin', 'admin'))
->addFlags(new WriteProtection(Context::SYSTEM_SCOPE)),