Overview
The /display_logo endpoint served files from the uploads directory without properly checking authorization. Anyone who knew or could guess a valid filename could retrieve a file without logging in.
Technical findings
The handler used a filename supplied in the request to serve content directly from the uploads directory. Authorization checks applied to other file endpoints were missing here.
This is clearly an access-control issue. A filename is not a security boundary; the server should have protected the resource.
Depending on the contents of the uploads directory, internal assets or other files could be exposed. The public CVE record describes the same unauthorized access through /display_logo.
Why it matters
No active session is required. A valid or guessable filename is enough to request the resource directly. The severity depends on what files are stored in the uploads directory.
Potential impact
- Disclosure of files or assets from the uploads directory without authentication.
Remediation
- Upgrade to OpenAtlas 8.13.0 or later.
- Apply the same authentication and authorization logic to file-serving endpoints as to the rest of the application.
- Never rely on client-supplied filenames alone to decide whether access is permitted.
- Limit upload areas to content intended for publication and keep sensitive files outside web-accessible locations.
Affected and fixed versions
Disclosure timeline
- Discovery
Identified during an on-premises penetration test.
- Report submitted
Sent the finding and technical details to the vendor.
- Fix confirmed
The vendor reported that the issue had been fixed.
- CVE assignment
Received the CVE ID during coordinated disclosure.