Sceawere
Vulnerability Detail
CVE-2026-105180UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Jeebase Mass Assignment Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 16h ago
- Vendor
- n/a
- Product
- Jeebase
- Attack Type
- Dynamically-Determined Object Attributes
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was determined in Jeebase 0.0.1. This vulnerability affects the function updateUser of the file /user/update/info of the component UserService. Executing a manipulation of the argument user/tempUser can lead to dynamically-determined object attributes. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-10-05T02:16:50.217Z",
"pubdate": "2026-10-05T02:16:50.217Z",
"executiveSummary": "A critical mass assignment vulnerability exists in Jeebase 0.0.1 within the UserService component, specifically impacting the updateUser function.\nThis vulnerability allows remote attackers to manipulate internal object attributes that were not intended for client-side modification.\nBy injecting unauthorized parameters into the 'user/tempUser' argument, an attacker can influence the application's state, potentially leading to unauthorized privilege escalation or data tampering.\nThe flaw resides in the improper binding of request parameters to internal object properties without sufficient filtering or allow-listing.\nGiven that the exploit is publicly disclosed and the vendor has not responded to initial disclosures, the risk of active exploitation is significant.\nThe vulnerability is remotely exploitable, requiring no prior authentication or specific administrative privileges to execute the malicious payload.",
"technicalDetails": "The vulnerability originates from an insecure parameter binding implementation within the updateUser function located in /user/update/info of the UserService component.\nThe system fails to adequately sanitize or restrict the fields accepted in the user/tempUser argument, effectively enabling a mass assignment attack vector.\nWhen the application processes the request, it automatically maps incoming JSON or form-data parameters directly onto the underlying Java/Spring object model without explicit property exclusion.\nAn attacker can exploit this by crafting a malicious HTTP request that includes additional, sensitive attributes within the user/tempUser object that are usually reserved for internal system use or administrative modification.\nFor instance, by including fields like 'role', 'permissions', or 'isActive' in the request payload, an attacker can overwrite these attributes in the persistence layer during the update process.\nThe attack flow involves the following sequence: First, the attacker identifies the update endpoint /user/update/info as the target. Second, the attacker performs service reconnaissance to determine the object structure of the 'user/tempUser' entity. Third, the attacker transmits an HTTP request (typically via POST or PUT) containing the legitimate update parameters alongside the forged malicious attributes.\nBecause the application backend does not employ a Data Transfer Object (DTO) or a strict '@RequestBody' validation pattern (such as using an allow-list or '@InitBinder' to exclude sensitive fields), the framework indiscriminately updates the model object with the attacker-supplied values.\nThe post-exploitation impact includes the ability to elevate user privileges, bypass authorization checks, or manipulate application logic by altering flags that control user access or security state.\nThe vulnerability is accessible via remote network interfaces, and because there is no mechanism to verify the scope of the incoming object properties, the application is fundamentally susceptible to state-corruption attacks.\nThis behavior persists across the 0.0.1 version, representing a failure in secure input handling and design-time security controls."
}