CyberRota Analysis
AI-GeneratedThe vulnerability affects Capgo versions prior to 12.244.1, where an authenticated attacker can exploit a cross-tenant integrity flaw in the metadata-cleaning worker. By manipulating image object keys from mutable database rows, attackers can modify metadata of cross-tenant image objects without authorization, leading to potential data integrity issues. Organizations using Capgo should prioritize patching this vulnerability to prevent unauthorized metadata modifications and protect tenant data integrity.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Capgo before 12.244.1 contains a cross-tenant integrity vulnerability in the metadata-cleaning worker that trusts image object keys from mutable database rows without validating ownership. An authenticated attacker can place a victim tenant's image key in a row they control, causing the service-role worker to download and re-upload that object with sanitized metadata. Attackers can silently modify metadata in cross-tenant image objects by supplying known victim keys during authorized row updates, bypassing storage access controls through the confused-deputy metadata worker.