[jedit:bugs] #4147 Found Vulnerability:- IDOR (Insecure Direct Object Reference)

Eric Le Lay via jEdit-devel <[email protected]> Mon, 15 Sep 2025 18:53:48 -0000
Newsgroups gmane.editors.jedit.devel
Message-ID </p/jedit/bugs/4147/dbab909a817a5504823a57368b6ef463ba5f0dcb.bugs@jedit.p.sourceforge.net>
This is a multi-part message in MIME format.
--===============7441060475211603799==
Content-Type: multipart/related; boundary="===============6281900492997559420=="

This is a multi-part message in MIME format.
--===============6281900492997559420==
Content-Type: multipart/alternative; boundary="===============3021394008682867890=="
MIME-Version: 1.0

--===============3021394008682867890==
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit

- **Group**: severe bug --> UNUSED
- **Comment**:

please clarify exactly how  in step 6. it is a vulnerability since the response is an error. Anyway, please send the report to sourceforge.net, because on jedit.org it is just an image and a plain link to https://www.sourceforge.net/projects/jedit/.




---

**[bugs:#4147] Found Vulnerability:- IDOR (Insecure Direct Object Reference)**

**Status:** open-invalid
**Group:** UNUSED
**Labels:** IDOR (Insecure Direct Object Reference) 
**Created:** Thu Sep 11, 2025 08:58 PM UTC by kunal waidande 
**Last Updated:** Mon Sep 15, 2025 06:53 PM UTC
**Owner:** nobody
**Attachments:**

- [jedit.org report.pdf](https://sourceforge.net/p/jedit/bugs/4147/attachment/jedit.org%20report.pdf) (920.8 kB; application/pdf)


The following API endpoint allows an attacker to change account-id in the query string and receive a valid response tied to that account.

Vulnerable endpoint: GET /a/api/fastlane.json?account_id=15680&site_id=103240

How to perform:
1- Go to website (https://www.jedit.org)
2- In home page on right side you will see sourceForge Project option.
3- Open burpsuit and on the intercept and in browser click on sourceForge Project option.
4- Forward the first and second request and then you will see bunch of requests in that request.
5- You that requests you will see (https://fastlane.rubiconproject.com).
6- Send it to repeater and change the account id.
7- You will see that response is 200 OK .

Please find attached PDF report in that, I have created all the manually tested proof report.


---

Sent from sourceforge.net because [email protected] is subscribed to https://sourceforge.net/p/jedit/bugs/

To unsubscribe from further messages, a project admin can change settings at https://sourceforge.net/p/jedit/admin/bugs/options.  Or, if this is a mailing list, you can unsubscribe from the mailing list.
--===============3021394008682867890==
MIME-Version: 1.0
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: 7bit

<div class="markdown_content"><ul>
<li><strong>Group</strong>: severe bug --&gt; UNUSED</li>
<li><strong>Comment</strong>:</li>
</ul>
<p>please clarify exactly how  in step 6. it is a vulnerability since the response is an error. Anyway, please send the report to sourceforge.net, because on jedit.org it is just an image and a plain link to <a href="https://www.sourceforge.net/projects/jedit/." rel="nofollow">https://www.sourceforge.net/projects/jedit/.</a></p>
<hr/>
<p><strong><a class="alink" href="https://sourceforge.net/p/jedit/bugs/4147/">[bugs:#4147]</a> Found Vulnerability:- IDOR (Insecure Direct Object Reference)</strong></p>
<p><strong>Status:</strong> open-invalid<br/>
<strong>Group:</strong> UNUSED<br/>
<strong>Labels:</strong> IDOR (Insecure Direct Object Reference) <br/>
<strong>Created:</strong> Thu Sep 11, 2025 08:58 PM UTC by kunal waidande <br/>
<strong>Last Updated:</strong> Mon Sep 15, 2025 06:53 PM UTC<br/>
<strong>Owner:</strong> nobody<br/>
<strong>Attachments:</strong></p>
<ul>
<li><a class="" href="https://sourceforge.net/p/jedit/bugs/4147/attachment/jedit.org%20report.pdf">jedit.org report.pdf</a> (920.8 kB; application/pdf)</li>
</ul>
<p>The following API endpoint allows an attacker to change account-id in the query string and receive a valid response tied to that account.</p>
<p>Vulnerable endpoint: GET /a/api/fastlane.json?account_id=15680&amp;site_id=103240</p>
<p>How to perform:<br/>
1- Go to website (https://www.jedit.org)<br/>
2- In home page on right side you will see sourceForge Project option.<br/>
3- Open burpsuit and on the intercept and in browser click on sourceForge Project option.<br/>
4- Forward the first and second request and then you will see bunch of requests in that request.<br/>
5- You that requests you will see (https://fastlane.rubiconproject.com).<br/>
6- Send it to repeater and change the account id.<br/>
7- You will see that response is 200 OK .</p>
<p>Please find attached PDF report in that, I have created all the manually tested proof report.</p>
<hr/>
<p>Sent from sourceforge.net because [email protected] is subscribed to <a href="https://sourceforge.net/p/jedit/bugs/">https://sourceforge.net/p/jedit/bugs/</a></p>
<p>To unsubscribe from further messages, a project admin can change settings at <a href="https://sourceforge.net/p/jedit/admin/bugs/options.">https://sourceforge.net/p/jedit/admin/bugs/options.</a>  Or, if this is a mailing list, you can unsubscribe from the mailing list.</p></div>
--===============3021394008682867890==--

--===============6281900492997559420==--


--===============7441060475211603799==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============7441060475211603799==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-- 
-----------------------------------------------
jEdit Developers' List
[email protected]
https://lists.sourceforge.net/lists/listinfo/jedit-devel

--===============7441060475211603799==--