[jedit:bugs] #4147 Found Vulnerability:- IDOR (Insecure Direct Object Reference)
Eric Le Lay via jEdit-devel <[email protected]> Mon, 15 Sep 2025 18:53:48 -0000
| Newsgroups | gmane.editors.jedit.devel |
|---|---|
| Message-ID | </p/jedit/bugs/4147/dbab909a817a5504823a57368b6ef463ba5f0dcb.bugs@jedit.p.sourceforge.net> |
This is a multi-part message in MIME format. --===============7441060475211603799== Content-Type: multipart/related; boundary="===============6281900492997559420==" This is a multi-part message in MIME format. --===============6281900492997559420== Content-Type: multipart/alternative; boundary="===============3021394008682867890==" MIME-Version: 1.0 --===============3021394008682867890== MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit - **Group**: severe bug --> UNUSED - **Comment**: please clarify exactly how in step 6. it is a vulnerability since the response is an error. Anyway, please send the report to sourceforge.net, because on jedit.org it is just an image and a plain link to https://www.sourceforge.net/projects/jedit/. --- **[bugs:#4147] Found Vulnerability:- IDOR (Insecure Direct Object Reference)** **Status:** open-invalid **Group:** UNUSED **Labels:** IDOR (Insecure Direct Object Reference) **Created:** Thu Sep 11, 2025 08:58 PM UTC by kunal waidande **Last Updated:** Mon Sep 15, 2025 06:53 PM UTC **Owner:** nobody **Attachments:** - [jedit.org report.pdf](https://sourceforge.net/p/jedit/bugs/4147/attachment/jedit.org%20report.pdf) (920.8 kB; application/pdf) The following API endpoint allows an attacker to change account-id in the query string and receive a valid response tied to that account. Vulnerable endpoint: GET /a/api/fastlane.json?account_id=15680&site_id=103240 How to perform: 1- Go to website (https://www.jedit.org) 2- In home page on right side you will see sourceForge Project option. 3- Open burpsuit and on the intercept and in browser click on sourceForge Project option. 4- Forward the first and second request and then you will see bunch of requests in that request. 5- You that requests you will see (https://fastlane.rubiconproject.com). 6- Send it to repeater and change the account id. 7- You will see that response is 200 OK . Please find attached PDF report in that, I have created all the manually tested proof report. --- Sent from sourceforge.net because [email protected] is subscribed to https://sourceforge.net/p/jedit/bugs/ To unsubscribe from further messages, a project admin can change settings at https://sourceforge.net/p/jedit/admin/bugs/options. Or, if this is a mailing list, you can unsubscribe from the mailing list. --===============3021394008682867890== MIME-Version: 1.0 Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: 7bit <div class="markdown_content"><ul> <li><strong>Group</strong>: severe bug --> UNUSED</li> <li><strong>Comment</strong>:</li> </ul> <p>please clarify exactly how in step 6. it is a vulnerability since the response is an error. Anyway, please send the report to sourceforge.net, because on jedit.org it is just an image and a plain link to <a href="https://www.sourceforge.net/projects/jedit/." rel="nofollow">https://www.sourceforge.net/projects/jedit/.</a></p> <hr/> <p><strong><a class="alink" href="https://sourceforge.net/p/jedit/bugs/4147/">[bugs:#4147]</a> Found Vulnerability:- IDOR (Insecure Direct Object Reference)</strong></p> <p><strong>Status:</strong> open-invalid<br/> <strong>Group:</strong> UNUSED<br/> <strong>Labels:</strong> IDOR (Insecure Direct Object Reference) <br/> <strong>Created:</strong> Thu Sep 11, 2025 08:58 PM UTC by kunal waidande <br/> <strong>Last Updated:</strong> Mon Sep 15, 2025 06:53 PM UTC<br/> <strong>Owner:</strong> nobody<br/> <strong>Attachments:</strong></p> <ul> <li><a class="" href="https://sourceforge.net/p/jedit/bugs/4147/attachment/jedit.org%20report.pdf">jedit.org report.pdf</a> (920.8 kB; application/pdf)</li> </ul> <p>The following API endpoint allows an attacker to change account-id in the query string and receive a valid response tied to that account.</p> <p>Vulnerable endpoint: GET /a/api/fastlane.json?account_id=15680&site_id=103240</p> <p>How to perform:<br/> 1- Go to website (https://www.jedit.org)<br/> 2- In home page on right side you will see sourceForge Project option.<br/> 3- Open burpsuit and on the intercept and in browser click on sourceForge Project option.<br/> 4- Forward the first and second request and then you will see bunch of requests in that request.<br/> 5- You that requests you will see (https://fastlane.rubiconproject.com).<br/> 6- Send it to repeater and change the account id.<br/> 7- You will see that response is 200 OK .</p> <p>Please find attached PDF report in that, I have created all the manually tested proof report.</p> <hr/> <p>Sent from sourceforge.net because [email protected] is subscribed to <a href="https://sourceforge.net/p/jedit/bugs/">https://sourceforge.net/p/jedit/bugs/</a></p> <p>To unsubscribe from further messages, a project admin can change settings at <a href="https://sourceforge.net/p/jedit/admin/bugs/options.">https://sourceforge.net/p/jedit/admin/bugs/options.</a> Or, if this is a mailing list, you can unsubscribe from the mailing list.</p></div> --===============3021394008682867890==-- --===============6281900492997559420==-- --===============7441060475211603799== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============7441060475211603799== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline -- ----------------------------------------------- jEdit Developers' List [email protected] https://lists.sourceforge.net/lists/listinfo/jedit-devel --===============7441060475211603799==--