[jedit:bugs] #4147 Found Vulnerability:- IDOR (Insecure Direct Object Reference)
kunal waidande via jEdit-devel <[email protected]> Thu, 11 Sep 2025 20:58:46 -0000
| Newsgroups | gmane.editors.jedit.devel |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format. --===============2157036558958518822== Content-Type: multipart/related; boundary="===============2009261056060397022==" This is a multi-part message in MIME format. --===============2009261056060397022== Content-Type: multipart/alternative; boundary="===============8727221059665171742==" MIME-Version: 1.0 --===============8727221059665171742== MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit --- **[bugs:#4147] Found Vulnerability:- IDOR (Insecure Direct Object Reference)** **Status:** open **Group:** severe bug **Labels:** IDOR (Insecure Direct Object Reference) **Created:** Thu Sep 11, 2025 08:58 PM UTC by kunal waidande **Last Updated:** Thu Sep 11, 2025 08:58 PM UTC **Owner:** nobody **Attachments:** - [jedit.org report.pdf](https://sourceforge.net/p/jedit/bugs/4147/attachment/jedit.org%20report.pdf) (920.8 kB; application/pdf) The following API endpoint allows an attacker to change account-id in the query string and receive a valid response tied to that account. Vulnerable endpoint: GET /a/api/fastlane.json?account_id=15680&site_id=103240 How to perform: 1- Go to website (https://www.jedit.org) 2- In home page on right side you will see sourceForge Project option. 3- Open burpsuit and on the intercept and in browser click on sourceForge Project option. 4- Forward the first and second request and then you will see bunch of requests in that request. 5- You that requests you will see (https://fastlane.rubiconproject.com). 6- Send it to repeater and change the account id. 7- You will see that response is 200 OK . Please find attached PDF report in that, I have created all the manually tested proof report. --- Sent from sourceforge.net because [email protected] is subscribed to https://sourceforge.net/p/jedit/bugs/ To unsubscribe from further messages, a project admin can change settings at https://sourceforge.net/p/jedit/admin/bugs/options. Or, if this is a mailing list, you can unsubscribe from the mailing list. --===============8727221059665171742== MIME-Version: 1.0 Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: 7bit <div class="markdown_content"><hr/> <p><strong><a class="alink" href="https://sourceforge.net/p/jedit/bugs/4147/">[bugs:#4147]</a> Found Vulnerability:- IDOR (Insecure Direct Object Reference)</strong></p> <p><strong>Status:</strong> open<br/> <strong>Group:</strong> severe bug<br/> <strong>Labels:</strong> IDOR (Insecure Direct Object Reference) <br/> <strong>Created:</strong> Thu Sep 11, 2025 08:58 PM UTC by kunal waidande <br/> <strong>Last Updated:</strong> Thu Sep 11, 2025 08:58 PM UTC<br/> <strong>Owner:</strong> nobody<br/> <strong>Attachments:</strong></p> <ul> <li><a class="" href="https://sourceforge.net/p/jedit/bugs/4147/attachment/jedit.org%20report.pdf">jedit.org report.pdf</a> (920.8 kB; application/pdf)</li> </ul> <p>The following API endpoint allows an attacker to change account-id in the query string and receive a valid response tied to that account.</p> <p>Vulnerable endpoint: GET /a/api/fastlane.json?account_id=15680&site_id=103240</p> <p>How to perform:<br/> 1- Go to website (https://www.jedit.org)<br/> 2- In home page on right side you will see sourceForge Project option.<br/> 3- Open burpsuit and on the intercept and in browser click on sourceForge Project option.<br/> 4- Forward the first and second request and then you will see bunch of requests in that request.<br/> 5- You that requests you will see (https://fastlane.rubiconproject.com).<br/> 6- Send it to repeater and change the account id.<br/> 7- You will see that response is 200 OK .</p> <p>Please find attached PDF report in that, I have created all the manually tested proof report.</p> <hr/> <p>Sent from sourceforge.net because [email protected] is subscribed to <a href="https://sourceforge.net/p/jedit/bugs/">https://sourceforge.net/p/jedit/bugs/</a></p> <p>To unsubscribe from further messages, a project admin can change settings at <a href="https://sourceforge.net/p/jedit/admin/bugs/options.">https://sourceforge.net/p/jedit/admin/bugs/options.</a> Or, if this is a mailing list, you can unsubscribe from the mailing list.</p></div> --===============8727221059665171742==-- --===============2009261056060397022==-- --===============2157036558958518822== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============2157036558958518822== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline -- ----------------------------------------------- jEdit Developers' List [email protected] https://lists.sourceforge.net/lists/listinfo/jedit-devel --===============2157036558958518822==--