All incidents

Bug bounty results

Bug Bounty: multiple vulnerabilities

Vulnerability #1: Stored XSS on first/last name during setup

Summary

Product affected:Passbolt API Community Edition, Pro Edition, Passbolt Cloud
Version affected:v2.10 and below.
Version fixed:v2.11
Affected component:Setup or recovery start page.
Vulnerability Type:Cross-site Scripting (XSS) - Stored (CWE-79)
CVSS Score:6.8 (High)

Description

<svg onload="confirm(document.domain)">'); ?></svg>

Impact of issue

Fix

Vulnerability #2: Stored XSS in tags autocomplete dropdown

Summary

Product affected:Passbolt API Pro Edition, Passbolt Cloud
Version affected:v2.10 and below.
Version fixed:v2.11
Affected component:Tag form autocomplete.
Vulnerability Type:Cross-site Scripting (XSS) - Stored (CWE-79)
CVSS Score:8 (High)

Description

Impact of issue

Fix

Vulnerability #3: Tabnabbing when opening URI with menu "Open URI in a new tab"

Summary

Product affected:Passbolt API Pro Edition, Passbolt Cloud
Version affected:v2.10 and below.
Version fixed:v2.11
Affected component:Password grid URI “open in a new tab” functionality.
Vulnerability Type:Violation of Secure Design Principles (CWE-657)
CVSS Score:5 (Medium)

Description

Impact of issue

Fix

Vulnerability #4: OS Command Injection in CSV file export (Won’t Fix)

Summary

Product affected:Passbolt Web Extension & Microsoft Excel or similar
Version affected:v2.10 and below.
Version fixed:Won't fix
Affected component:CSV file export.
Vulnerability Type:OS Command Injection (CWE-78)
CVSS Score:5 (Medium)

Description

=cmd|' /C notepad'!'A1'

Impact of issue

Fix

Event timeline

  • 2019-07-30: Security researcher notifies passbolt team about the issues.
  • 2019-08-01: Security researcher notifies an additional issue.
  • 2019-08-01: Passbolt acknowledges the issue and start working on a fix.
  • 2019-08-05: Fixes are ready and included as part of v2.11 release UAT.
  • 2019-08-07: Passbolt publishes a fix.
Last updated: 2019-08-07 16:00:00 CET
Flag of European UnionMade in Europe. Privacy by default.
Passbolt Security Incident Report: audit - August 7th, 2019