[jedit:bugs] #4147 Found Vulnerability:- IDOR (Insecure Direct Object Reference)

Eric Le Lay via jEdit-devel <[email protected]> Wed, 17 Sep 2025 12:28:03 -0000
Newsgroups gmane.editors.jedit.devel
Message-ID </p/jedit/bugs/4147/67722f336793e821908bf4dc8576f718d15d58dd.bugs@jedit.p.sourceforge.net>
This is a multi-part message in MIME format.
--===============0118912293697586706==
Content-Type: multipart/related; boundary="===============1995699923401633488=="

This is a multi-part message in MIME format.
--===============1995699923401633488==
Content-Type: multipart/alternative; boundary="===============0965776203217858728=="
MIME-Version: 1.0

--===============0965776203217858728==
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit

- **status**: open-invalid --> closed-invalid
- **Comment**:

according to your report HTTP is 200 with modified or unmodified account id, but json is status: "ok" with unmodified and "error" with modified account id. So it doesn't look like the changed account id was accepted.
Again, it has nothing to do with jEdit. I'm closing the ticket now.



---

**[bugs:#4147] Found Vulnerability:- IDOR (Insecure Direct Object Reference)**

**Status:** closed-invalid
**Group:** UNUSED
**Labels:** IDOR (Insecure Direct Object Reference) 
**Created:** Thu Sep 11, 2025 08:58 PM UTC by kunal waidande 
**Last Updated:** Tue Sep 16, 2025 01:57 PM UTC
**Owner:** nobody
**Attachments:**

- [jedit.org report.pdf](https://sourceforge.net/p/jedit/bugs/4147/attachment/jedit.org%20report.pdf) (920.8 kB; application/pdf)


The following API endpoint allows an attacker to change account-id in the query string and receive a valid response tied to that account.

Vulnerable endpoint: GET /a/api/fastlane.json?account_id=15680&site_id=103240

How to perform:
1- Go to website (https://www.jedit.org)
2- In home page on right side you will see sourceForge Project option.
3- Open burpsuit and on the intercept and in browser click on sourceForge Project option.
4- Forward the first and second request and then you will see bunch of requests in that request.
5- You that requests you will see (https://fastlane.rubiconproject.com).
6- Send it to repeater and change the account id.
7- You will see that response is 200 OK .

Please find attached PDF report in that, I have created all the manually tested proof report.


---

Sent from sourceforge.net because [email protected] is subscribed to https://sourceforge.net/p/jedit/bugs/

To unsubscribe from further messages, a project admin can change settings at https://sourceforge.net/p/jedit/admin/bugs/options.  Or, if this is a mailing list, you can unsubscribe from the mailing list.
--===============0965776203217858728==
MIME-Version: 1.0
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: 7bit

<div class="markdown_content"><ul>
<li><strong>status</strong>: open-invalid --&gt; closed-invalid</li>
<li><strong>Comment</strong>:</li>
</ul>
<p>according to your report HTTP is 200 with modified or unmodified account id, but json is status: "ok" with unmodified and "error" with modified account id. So it doesn't look like the changed account id was accepted.<br/>
Again, it has nothing to do with jEdit. I'm closing the ticket now.</p>
<hr/>
<p><strong><a class="alink strikethrough" href="https://sourceforge.net/p/jedit/bugs/4147/">[bugs:#4147]</a> Found Vulnerability:- IDOR (Insecure Direct Object Reference)</strong></p>
<p><strong>Status:</strong> closed-invalid<br/>
<strong>Group:</strong> UNUSED<br/>
<strong>Labels:</strong> IDOR (Insecure Direct Object Reference) <br/>
<strong>Created:</strong> Thu Sep 11, 2025 08:58 PM UTC by kunal waidande <br/>
<strong>Last Updated:</strong> Tue Sep 16, 2025 01:57 PM UTC<br/>
<strong>Owner:</strong> nobody<br/>
<strong>Attachments:</strong></p>
<ul>
<li><a class="" href="https://sourceforge.net/p/jedit/bugs/4147/attachment/jedit.org%20report.pdf">jedit.org report.pdf</a> (920.8 kB; application/pdf)</li>
</ul>
<p>The following API endpoint allows an attacker to change account-id in the query string and receive a valid response tied to that account.</p>
<p>Vulnerable endpoint: GET /a/api/fastlane.json?account_id=15680&amp;site_id=103240</p>
<p>How to perform:<br/>
1- Go to website (https://www.jedit.org)<br/>
2- In home page on right side you will see sourceForge Project option.<br/>
3- Open burpsuit and on the intercept and in browser click on sourceForge Project option.<br/>
4- Forward the first and second request and then you will see bunch of requests in that request.<br/>
5- You that requests you will see (https://fastlane.rubiconproject.com).<br/>
6- Send it to repeater and change the account id.<br/>
7- You will see that response is 200 OK .</p>
<p>Please find attached PDF report in that, I have created all the manually tested proof report.</p>
<hr/>
<p>Sent from sourceforge.net because [email protected] is subscribed to <a href="https://sourceforge.net/p/jedit/bugs/">https://sourceforge.net/p/jedit/bugs/</a></p>
<p>To unsubscribe from further messages, a project admin can change settings at <a href="https://sourceforge.net/p/jedit/admin/bugs/options.">https://sourceforge.net/p/jedit/admin/bugs/options.</a>  Or, if this is a mailing list, you can unsubscribe from the mailing list.</p></div>
--===============0965776203217858728==--

--===============1995699923401633488==--


--===============0118912293697586706==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============0118912293697586706==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-- 
-----------------------------------------------
jEdit Developers' List
[email protected]
https://lists.sourceforge.net/lists/listinfo/jedit-devel

--===============0118912293697586706==--