VYPR
Medium severity5.3OSV Advisory· Published Dec 21, 2018· Updated Jun 17, 2026

CVE-2018-20345

CVE-2018-20345

Description

Incorrect access control in StackStorm API (st2api) in StackStorm before 2.9.2 and 2.10.x before 2.10.1 allows an attacker (who has a StackStorm account and is authenticated against the StackStorm API) to retrieve datastore items for other users by utilizing the /v1/keys "?scope=all" and "?user=" query filter parameters. Enterprise editions with RBAC enabled are not affected.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:stackstorm:stackstorm:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:stackstorm:stackstorm:*:*:*:*:*:*:*:*range: <2.9.2
    • (no CPE)range: <2.9.2, <2.10.1
  • Range: v2.10.0, v2.9.0, v2.9.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.