Skip to content

SKA security advisory: insufficient validation of group access rule edit privileges

Thomas Pike edited this page Sep 15, 2025 · 4 revisions

Previously, /groups/{group}/access_rules/{id} accepted POSTs from any authenticated user, allowing them to overwrite SSH authorized_keys options for all group members, regardless of whether they are in the specified group or not. This exposed a privilege escalation vector and risk of access disruption.

This issue was identified and resolved by MegaManSec in #78.

Clone this wiki locally