From d03f6077ddf85ad448cbcb2145341d9543fc4711 Mon Sep 17 00:00:00 2001 From: Bryan Frimin Date: Fri, 3 Jul 2026 12:11:22 +0200 Subject: [PATCH] Document disclosed IDOR and GraphQL DoS advisories Add SECURITY_NOTES.md entries for GHSA-c74x-79w6-63jh (cross-tenant IDOR via unvalidated Finding->Risk and ProcessingActivity->DPO references) and GHSA-prh2-g8pv-m7p9 (GraphQL alias-flooding DoS), ahead of public disclosure. Signed-off-by: Bryan Frimin --- SECURITY_NOTES.md | 46 ++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 46 insertions(+) diff --git a/SECURITY_NOTES.md b/SECURITY_NOTES.md index d4f6f7d33..4e0fe838d 100644 --- a/SECURITY_NOTES.md +++ b/SECURITY_NOTES.md @@ -3,6 +3,52 @@ User-facing notes on security-relevant changes to Probo. For the vulnerability reporting process, see [SECURITY.md](SECURITY.md). +## Cross-tenant IDOR via unvalidated foreign-key references + +_2026-07-03, GraphQL_ + +Two console GraphQL resolvers authorized the parent object and then +resolved a related object with a tenant scope taken from that related +object's own GID, instead of from the authorization result. An +authenticated member of one organization could attach another +organization's Risk or Data Protection Officer profile GID to their own +Finding or Processing Activity, then read it back: + +- `Finding.risk` disclosed another organization's Risk (name, + description, treatment, category, severity, owner). +- `ProcessingActivity.dataProtectionOfficer` disclosed another + organization's person profile PII (full name, email addresses, + position). + +`FindingService` and `ProcessingActivityService` now validate the +referenced Risk and Data Protection Officer profile against the +caller's scope before storing the reference, and the affected +resolvers (along with every other resolver following the same +pattern) now authorize the related object's own ID rather than the +parent's. + +Reported by [Pig-Tail](https://github.com/Pig-Tail). +([GHSA-c74x-79w6-63jh](https://github.com/getprobo/probo/security/advisories/GHSA-c74x-79w6-63jh)) + +## GraphQL alias-flooding denial of service + +_2026-06-29, GraphQL_ + +The GraphQL endpoints (`connect`, `console`, and `trust`) built their +server with no limits on query size or complexity. A single request +containing thousands of aliased resolver calls (e.g. `a1: viewer { id +}` repeated thousands of times) was parsed, executed, and marshalled +in full, letting an attacker drive excessive CPU and memory use and +degrade service for other tenants. + +The shared GraphQL handler now enforces a parser token limit that +rejects oversized queries before execution, a fixed query complexity +limit, and an LRU query cache, with limits configurable per +environment via `PROBOD_API_GRAPHQL_*` env vars and Helm values. + +Reported by [Muthu-Devarajan](https://github.com/Muthu-Devarajan). +([GHSA-prh2-g8pv-m7p9](https://github.com/getprobo/probo/security/advisories/GHSA-prh2-g8pv-m7p9)) + ## Open redirect bypass in saferedirect _2026-05-26, Auth_