<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:casdoor:casdoor:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3acasdoorcasdoor/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 02 Sep 2026 01:10:40 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3acasdoorcasdoor/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in Casdoor Upload Resource API</title><link>https://feed.craftedsignal.io/briefs/2026-09-casdoor-auth-bypass/</link><pubDate>Wed, 02 Sep 2026 01:10:40 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-casdoor-auth-bypass/</guid><description>Casdoor versions up to 4.0.0 contain an authentication bypass vulnerability in the upload-resource API that permits remote, unauthenticated file operations.</description><content:encoded><![CDATA[<p>Casdoor versions up to 4.0.0 are vulnerable to an authentication bypass vulnerability within the upload-resource API component, specifically located in the controllers/resource.go file. This flaw stems from missing authentication checks, which allows remote, unauthenticated attackers to interact with the API. The vulnerability poses a significant risk as it provides a mechanism for unauthorized file operations, potentially leading to unauthorized data exposure or malicious file uploads. Public exploit material exists for this vulnerability. Security researchers reported that the vendor removed the associated issue tracking the bug from GitHub without explanation and failed to respond to private disclosure attempts, indicating a lack of forthcoming vendor patches or guidance. Organizations using Casdoor should immediately evaluate exposure of the affected API endpoint and implement compensatory network controls to restrict access.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an unauthenticated remote attacker to bypass intended access controls within the Casdoor resource management module. This unauthorized access can lead to the manipulation of resources, arbitrary file uploads, or exfiltration of sensitive information depending on the scope of the API's functionality. Given the lack of a vendor-provided patch, deployments are at risk of active exploitation by threat actors leveraging the publicly available exploit code.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Implement strict network-level access control lists (ACLs) to restrict access to the Casdoor API endpoints to trusted administrative IP ranges.</li>
<li>Monitor web server access logs for anomalous POST requests directed at the resource upload API paths, specifically investigating any requests originating from untrusted or non-authenticated sessions.</li>
<li>If the functionality is not business-critical, disable the resource upload API until the vendor provides a remediation or security update.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>vulnerability</category><category>authentication-bypass</category><category>webserver</category></item></channel></rss>