The user creation endpoint (POST /user) in Gotify versions 3.0.0 to 3.1.0 does not require an elevated session. An attacker in possession of a valid client token of an admin user can create new users, including new admin users, without knowing the admin's password. This bypasses the step-up authentication introduced in 3.0.0 for this endpoint.
Mitigation
- Upgrade to Gotify 3.1.1
- Restrict access to the state-changing endpoints under /user to trusted networks.
The user creation endpoint (POST /user) in Gotify versions 3.0.0 to 3.1.0 does not require an elevated session. An attacker in possession of a valid client token of an admin user can create new users, including new admin users, without knowing the admin's password. This bypasses the step-up authentication introduced in 3.0.0 for this endpoint.
Mitigation