T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/vw-update.sh:24- Finding
Collection Scope Is Not Enforced for Direct Item Operations
- Content
View full analysis
/dev/null) if [ -z "$CURRENT" ]; then echo "error: item '$ITEM_ID' not found" >&2 _vw_log "update" "$ITEM_ID:$FIELD" "not-found" exit 1 fi ITEM_NAME=$(echo "$CURRENT" | jq -r '.name') echo "$UPDATED" | bw encode | bw edit item "$ITEM_ID" > /dev/null ``` `scripts/vw-delete.sh:18-32`: ```bash # Fetch and confirm name matches ACTUAL_NAME=$(bw get item "$ITEM_ID" 2>/dev/null | jq -r '.name') if [ -z "$ACTUAL_NAME" ] || [ "$ACTUAL_NAME" = "null" ]; then echo "error: item '$ITEM_ID' not found" >&2 _vw_log "delete" "$ITEM_ID" "not-found" exit 1 fi if [ "$ACTUAL_NAME" != "$EXPECTED_NAME" ]; then echo "error: name mismatch — expected '$EXPECTED_NAME', got '$ACTUAL_NAME'. Delete aborted." >&2 _vw_log "delete" "$ITEM_ID" "name-mismatch" exit 1 fi bw delete item "$ITEM_ID" ``` `scripts/vw-rotate-pass.sh:14-35`: ```bash # Resolve item ITEM=$(bw get item "$1" 2>/dev/null) if [ -z "$ITEM" ]; then echo "error: item '$1' not found" >&2 _vw_cache_clear _vw_log "rotate-pass" "$1" "not-found" exit 1 fi ITEM_ID=$(echo "$ITEM" | jq -r '.id') ITEM_NAME=$(echo "$ITEM" | jq -r '.name') # Generate new password NEW_PASS=$(bw generate --length "$LENGTH" --uppercase --lowercase --number --special) # Upda ...[truncated 2340 chars]- Remediation
View remediation
&2 exit 1 fi fi ``` 3. Apply the check consistently in `vw-get.sh`, `vw-get-field.sh`, `vw-get-totp.sh`, `vw-update.sh`, `vw-delete.sh`, and `vw-rotate-pass.sh`. 4. For TOTP operations, first retrieve and authorize the item, then request the TOTP using the validated item ID. 5. Make full-vault fallback an explicit configuration option rather than silently enabling it when collection lookup fails. 6. Distinguish a legitimate personal-vault result from transient lookup, authentication, parsing, or network failures. Fail closed when the reason for an empty collection ID is uncertain. 7. Add tests proving that out-of-collection item IDs are rejected for every operation. ]]>
