fleetbase/fleetops-api is vulnerable to Improper Authorization
53
Medium Risk
FuelProviderService::ingestTransaction reconciles incoming fuel provider transactions with updateOrCreate using only provider and provider_transaction_id as the lookup key. Provider transaction ids are unique only within the account that issued them, so a transaction whose id collides with another company's record updates and reassigns that existing record instead of creating a new one. This lets one tenant overwrite or take over fuel transaction records belonging to a different company. The fix adds company_uuid to the lookup key and makes the backing unique index tenant and soft-delete aware.
You are affected if you are using a version that falls within the vulnerable range and your deployment ingests fuel provider transactions for more than one company.
fleetbase/fleetops-api is vulnerable to Improper Authorization in versions 0.6.52 - 0.6.59.
Upgrade the fleetbase/fleetops-api library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.