CyberRota Analysis
AI-GeneratedRainbond versions up to 6.9.7 are vulnerable due to a broken access control flaw in the CheckToken function, enabling authenticated attackers to manipulate URL paths and access unauthorized resources belonging to other enterprises. This vulnerability allows attackers to bypass enterprise ID verification using valid API tokens, potentially leading to unauthorized access or modification of critical services and configurations. Organizations using affected versions should prioritize remediation to protect sensitive enterprise data and maintain security integrity.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauthorized enterprise resources by substituting another enterprise's tenant name in URL paths. Attackers can use any valid API token to bypass enterprise ID verification and access or modify another enterprise's services, plugins, environment variables, and certificates.