Skip to content

[Backend] IDOR: loan-owner check compares a value to itself #1365

Description

@ogazboiz

Questions or want to claim this? Say hi in the community chat: https://t.me/+DOylgFv1jyJlNzM0

Description

requireLoanOwner compares the caller key to itself instead of to the loan's owner, so any user can operate on any loan.

Component: Backend
Location: backend/src/middleware/loanAccess.ts -> requireLoanOwner
Severity: Critical

How to reproduce / find it

As one user, invoke an owner-only loan operation on another user's loan.

Expected behavior

The loan's stored owner must match the caller.

Notes for contributors

This is a logic/behavior defect, not a compile error. Please open one PR per fix that references this issue and names the file and function above.

Metadata

Metadata

Assignees

Labels

GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26Stellar WaveIssues in the Stellar wave programbackendIssues related to backend developmentbugSomething isn't workingcriticalHigh-impact / hard issuesecuritySecurity related issues

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions