GHSA-72h8-wp98-7hch
Unleash: Missing await on permission check + cross-project IDOR in admin API
Quick fix
GHSA-72h8-wp98-7hch — unleash-server: upgrade to the fixed version with the command below.
npm install unleash-server@8.0.3Details
## Summary
Multiple authorization vulnerabilities in Unleash admin API, including a critical missing `await` that completely bypasses a permission check.
## Vulnerability 1: Missing `await` on Permission Check (HIGH)
**File:** `src/lib/features/segment/segment-controller.ts` (line 345)
`POST /api/admin/segments/strategies` has `permission: NONE` at the route level. The handler performs its own check via `this.accessService.hasPermission()`, but **omits the `await` keyword**. Since `hasPermission()` is async (returns `Promise<boolean>`), the variable always receives a truthy Promise object. The `if (!hasFeatureStrategyPermission)` check never triggers.
```typescript // BUG: missing await - hasPermission() returns Promise<boolean> const hasFeatureStrategyPermission = this.accessService.hasPermission( req.user, UPDATE_FEATURE_STRATEGY, projectId, environmentId, ); if (!hasFeatureStrategyPermission) { // Always false - Promise is truthy! res.status(403).send(); return; } ```
**Impact:** Any authenticated user can modify segment assignments on ANY strategy across ALL projects.
**Fix:** Add `await`: `const hasFeatureStrategyPermission = await this.accessService.hasPermission(...)`
## Vulnerability 2: Cross-Project Variant Read (MEDIUM)
**File:** `src/lib/routes/admin-api/project/variants.ts` (line 213-223)
`GET /api/admin/projects/:projectId/features/:featureName/environments/:environment/variants` completely ignores `projectId`. `getVariantsOnEnv()` only uses `featureName` and `environment`.
**Impact:** Any authenticated user can read variant configs (names, weights, payloads) from any project.
## Vulnerability 3: Cross-Project Strategy Read (MEDIUM)
**File:** `src/lib/features/feature-toggle/feature-toggle-controller.ts` (line 1107-1116)
`GET .../strategies/:strategyId` ignores all params except `strategyId`. Any authenticated user can read any strategy's full configuration.
## Vulnerability 4: Cross-Project Environment Info Leak (MEDIUM)
**File:** `src/lib/features/feature-toggle/feature-toggle-service.ts` (line 1611)
`getEnvironmentInfo()` doesn't validate feature belongs to project. Compare with `getFeature()` which calls `validateFeatureBelongsToProject()`.
## Vulnerability 5: Cross-Project Tag Modification (LOW)
**File:** `src/lib/features/feature-toggle/feature-toggle-controller.ts` (line 576-596)
`PUT /:projectId/tags` accepts features array in body without validating they belong to projectId.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/Unleash/unleash/security/advisories/GHSA-72h8-wp98-7hch[WEB]
- https://github.com/Unleash/unleash/commit/7bb2829fc40791aa478e8ffca149c11b0f9cb05a[WEB]
- https://github.com/Unleash/unleash/commit/ace121c922d2e3eb6f68d95b0b6ab2fc8d824ea1[WEB]
- https://github.com/Unleash/unleash/commit/bea7effd3687425630423f662136d548e100154d[WEB]
- https://github.com/Unleash/unleash/commit/c93a963e95e1b7bf1bca2a7729282a48d0eb2f6a[WEB]
- https://github.com/Unleash/unleash/commit/dd61d0e10f5977a2e5de78df467c3a17c09fbcef[WEB]
- https://github.com/Unleash/unleash[PACKAGE]
- https://github.com/Unleash/unleash/releases/tag/v8.0.3[WEB]