OSV 1.4.0 · github-reviewed · 修改于 2026-08-18 00:36
发布时间
2026-08-18 00:36
GitHub 审查时间
2026-08-18 00:36
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/08/GHSA-p845-629j-rcj6/GHSA-p845-629j-rcj6.json
The admin passkey reset endpoint lacked the role-level authorization check used by comparable privileged account-protection endpoints. A lower-privileged administrator could attempt passkey reset operations against same-level or higher-privileged users, including root-level accounts.
If the target account had a passkey configured, a lower-privileged administrator could remove that authentication factor and weaken the target account's protection boundary. The attacker still needed administrator privileges, so the issue is rated Medium.
The vulnerable admin passkey reset behavior was present from the passkey feature introduction in v0.9.1.3 through versions before v1.0.0-rc.7.
This issue is fixed in v1.0.0-rc.7. The fix adds a canManageTargetRole check to AdminResetPasskey before passkey lookup or deletion, preventing lower-privileged administrators from operating on same-level or higher-privileged users.
If upgrading immediately is not possible, restrict admin access to trusted operators only and block DELETE /api/user/:id/reset_passkey at the reverse proxy or gateway except for root operators.
0936e2504655a5cbf7bc3c388f6d3e2bb24916d3.controller/passkey.go, controller/twofa.go, and router/api-router.go.