Unleash: Missing await on permission check + cross-project IDOR in admin API
Description
Summary
Multiple authorization vulnerabilities in Unleash admin API, including a critical missing await that completely bypasses a permission check.
Vulnerability 1: Missing await on Permission Check (HIGH)
File: src/lib/features/segment/segment-controller.ts (line 345)
POST /api/admin/segments/strategies has permission: NONE at the route level. The handler performs its own check via this.accessService.hasPermission(), but **omits the await keyword**. Since hasPermission() is async (returns Promise), the variable always receives a truthy Promise object. The if (!hasFeatureStrategyPermission) check never triggers.
// BUG: missing await - hasPermission() returns Promise
const hasFeatureStrategyPermission = this.accessService.hasPermission(
req.user, UPDATE_FEATURE_STRATEGY, projectId, environmentId,
);
if (!hasFeatureStrategyPermission) { // Always false - Promise is truthy!
res.status(403).send();
return;
}
Impact: Any authenticated user can modify segment assignments on ANY strategy across ALL projects.
Fix: Add await: const hasFeatureStrategyPermission = await this.accessService.hasPermission(...)
Vulnerability 2: Cross-Project Variant Read (MEDIUM)
File: src/lib/routes/admin-api/project/variants.ts (line 213-223)
GET /api/admin/projects/:projectId/features/:featureName/environments/:environment/variants completely ignores projectId. getVariantsOnEnv() only uses featureName and environment.
Impact: Any authenticated user can read variant configs (names, weights, payloads) from any project.
Vulnerability 3: Cross-Project Strategy Read (MEDIUM)
File: src/lib/features/feature-toggle/feature-toggle-controller.ts (line 1107-1116)
GET .../strategies/:strategyId ignores all params except strategyId. Any authenticated user can read any strategy's full configuration.
Vulnerability 4: Cross-Project Environment Info Leak (MEDIUM)
File: src/lib/features/feature-toggle/feature-toggle-service.ts (line 1611)
getEnvironmentInfo() doesn't validate feature belongs to project. Compare with getFeature() which calls validateFeatureBelongsToProject().
Vulnerability 5: Cross-Project Tag Modification (LOW)
File: src/lib/features/feature-toggle/feature-toggle-controller.ts (line 576-596)
PUT /:projectId/tags accepts features array in body without validating they belong to projectId.
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-72h8-wp98-7hchghsaADVISORY
- github.com/Unleash/unleash/commit/7bb2829fc40791aa478e8ffca149c11b0f9cb05aghsa
- github.com/Unleash/unleash/commit/ace121c922d2e3eb6f68d95b0b6ab2fc8d824ea1ghsa
- github.com/Unleash/unleash/commit/bea7effd3687425630423f662136d548e100154dghsa
- github.com/Unleash/unleash/commit/c93a963e95e1b7bf1bca2a7729282a48d0eb2f6aghsa
- github.com/Unleash/unleash/commit/dd61d0e10f5977a2e5de78df467c3a17c09fbcefghsa
- github.com/Unleash/unleash/releases/tag/v8.0.3ghsa
- github.com/Unleash/unleash/security/advisories/GHSA-72h8-wp98-7hchghsa
News mentions
0No linked articles in our index yet.