Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `PUT /api/v2/users/{user}/password` endpoint authorized only `ActionUpdatePersonal` and did not prevent a `user-admin` from resetting an `owner` account's password. It also did not require the current password when an admin reset another user's password. Exploitation requires the privileged `user-admin` role so practical risk is limited to deployments that grant `user-admin` to less trusted operators. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 prevents non-owner users from resetting the password of an account that holds the `owner` role. As a workaround, restrict the `user-admin` role to trusted administrators.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.29.17CPE matchmatch criteria | cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:* | ||
>= 2.30.0, < 2.32.7CPE matchmatch criteria | cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:* | ||
>= 2.33.0, < 2.33.8CPE matchmatch criteria | cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:* | ||
>= 2.34.0, < 2.34.2CPE matchmatch criteria | cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.