GSSA-2026-04-PR3QFFGITLAB-GSSA-2026-04-PR3QFFApril 25, 20264.3 Medium
IDOR on /api/loa/user/:userId and /api/strikes/user/:userId in cobc-events
Endpoints returning another user's LoA/strikes only required `view_own_*` permission and did not enforce that the caller owned the path parameter, allowing any authenticated host to read other users' history.
Affected (1)
- gelhaus-solutionscobc-events
- ≥ 0.0.0Fixed in 1.0.1
Mitigations
Workarounds
- Revoke `view_own_loa` and `view_own_strikes` from non-admin roles until upgrade. Users will lose visibility of their own strikes/LoA in the meantime.
Solutions
- Upgrade cobc-events to 1.0.1 or later.
Exploits
- Authenticated user with only `view_own_strikes` issues `GET /api/strikes/user/<other-user-id>` and receives the target user's strike history.
Overview
Endpoints returning another user's LoA/strikes only required view_own_* permission and did not enforce that the caller owned the path parameter, allowing any authenticated host to read other users' history.
Severity
CVSS v3
4.3 Medium
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- Low
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- Low
- Integrity
- None
- Availability
- None
Weaknesses (3)
References (3)
- Patch in src/routes/loa.js (Patch)
- Patch in src/routes/strikes.js (Patch)
- CWE-639: Authorization Bypass Through User-Controlled Key (Third-party advisory)
Credits (5)
- Enno GelhausFinder · egelhaus@ennogelhaus.de
- Enno GelhausAnalyst · egelhaus@ennogelhaus.de
- Enno GelhausRemediation developer · egelhaus@ennogelhaus.de
- Enno GelhausRemediation reviewer · egelhaus@ennogelhaus.de
- Claude (Anthropic) — automated audit assistantTool · https://claude.com
Context
Impacts
Information disclosure of strike and LoA history of other users
CAPEC-115
Timeline
- 04/25/2026 00:00
Internal security audit started
- 04/25/2026 06:00
Vulnerability identified during audit
- 04/25/2026 12:00
Patch developed and merged to main
- 04/25/2026 14:00
cobc-events 1.0.1 released
- 04/25/2026 15:00
Advisory published