ToolJet - Token Leakage via Referer Header
Vulnerability Description
ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If the user opens the invite link/signup link and then clicks on any external links within the page, it leaks the password set token/signup token in the referer header. Using these tokens the attacker can access the user’s account.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-23067
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- WhiteSource Vulnerability Research Team (WVR)
References
Affected Vendor
ToolJet
View all reports →