CyberRota Analysis
AI-GeneratedThe vulnerability affects the Coder platform, specifically the `UpsertWorkspaceApp` and `insertAgentApp` functions, which improperly handle agent IDs during workspace provisioning, allowing for unauthorized cross-workspace app assignments. This can lead to potential privilege escalation if exploited by users with elevated access, such as template authors or external provisioner operators. Organizations utilizing affected versions should prioritize upgrading to versions 2.29.7, 2.32.7, 2.33.8, or 2.34.2 to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `UpsertWorkspaceApp` overwrites an existing app's `agent_id` on a primary-key conflict and `insertAgentApp` accepts the app ID from the provisioner's `CompleteJob` payload without verifying it belongs to the workspace being built. `CompleteJob` runs under `dbauthz.AsProvisionerd` so the authorization layer does not block the cross-workspace upsert. Exploitation requires elevated access as a template author or external provisioner operator. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 verifies that any existing `workspace_apps` row matching the supplied ID belongs to the workspace being built and rejects cross-workspace agent reassignment. No known workarounds are available.
Related CVEs
Other vulnerabilities affecting the same vendor(s)