The classifier judged this item not relevant to AI security, so it is left out of lists, feeds, the API and dataset releases. If that is wrong, report a correction on this page.
GHSA-jq7h-wrvp-3rgx: pyLoad: Privilege revocation and password change through the REST API do not invalidate the user's session
- Identifier
- GHSA-jq7h-wrvp-3rgx
- Published
- Record updated
Summary
Revoking a user's privileges or changing their password through the pyLoad REST API does not invalidate that user's existing Flask session. Role and permission values are read from the session rather than the database, and the session-invalidation step added for GHSA-66hx-chf7-3332 exists only in the WebUI form handlers, not in Api.set_user_permission or Api.change_password, which are exposed at /api/<func>. In testing against pyload-ng 0.5.0b3.dev101, a demoted admin's session kept access to admin-only endpoints such as /api/set_config_value. The stale session can persist for webui.session_lifetime, which defaults to 44640 minutes.
Mitigation
The author suggests placing session invalidation beside the database write in the core API, so every caller of these operations is covered. Re-reading role and permission from the database on each request is mentioned as a more complete but larger change whose cost has not been measured.